VDB
Sign up
HIGH8.8

PYSEC-2026-716

Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV

Quick fix

PYSEC-2026-716 — opencv-contrib-python: upgrade to the fixed version with the command below.

pip install --upgrade 'opencv-contrib-python>=3.3.1.11'

Details

OpenCV (Open Source Computer Vision Library) through 3.3 (corresponding to OpenCV-Python 3.3.0.9) has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image file by using cv::imread, as demonstrated by the 4-buf-overflow-readData-memcpy test case.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/opencv-contrib-python
Introduced in: 0Fixed in: 3.3.1.11
Fixpip install --upgrade 'opencv-contrib-python>=3.3.1.11'

References