HIGH7.5
PYSEC-2026-2834
NULL Pointer Dereference in OpenCV.
Quick fix
PYSEC-2026-2834 — opencv-python-headless: upgrade to the fixed version with the command below.
pip install --upgrade 'opencv-python-headless>=4.1.1.26'Details
An issue was discovered in OpenCV before 4.1.1 (OpenCV-Python before 4.1.1.26). There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/opencv-python-headless
Introduced in:
0Fixed in: 4.1.1.26Fix
pip install --upgrade 'opencv-python-headless>=4.1.1.26'References
- https://nvd.nist.gov/vuln/detail/CVE-2019-14493[ADVISORY]
- https://github.com/opencv/opencv/issues/15127[WEB]
- https://github.com/opencv/opencv-python[PACKAGE]
- https://github.com/opencv/opencv/compare/371bba8...ddbd10c[WEB]
- https://lists.debian.org/debian-lts-announce/2021/10/msg00028.html[WEB]
- https://pypi.org/project/opencv-python-headless[PACKAGE]
- https://github.com/advisories/GHSA-3448-vrgh-85xr[ADVISORY]