VDB
Sign up
HIGH8.8

PYSEC-2026-2828

Out-of-bounds Write in OpenCV

Quick fix

PYSEC-2026-2828 — opencv-python: upgrade to the fixed version with the command below.

pip install --upgrade 'opencv-python>=4.2.0.32'

Details

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/opencv-python
Introduced in: 0Fixed in: 4.2.0.32
Fixpip install --upgrade 'opencv-python>=4.2.0.32'

References