CVE-2026-39919

Source
https://cve.org/CVERecord?id=CVE-2026-39919
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39919.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39919
Downstream
Published
2026-09-15T14:26:06Z
Modified
2026-09-17T08:08:34Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter
Details

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39919.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "10.08.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "10.08.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/artifexsoftware/ghostpdl

Affected ranges

Type
GIT
Repo
https://github.com/artifexsoftware/ghostpdl
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
chrisl-test
ghostpdl
ghostpdl-ebuild
ken_20220210_baseline
robin_test_ref
ghostpdl-1.*
ghostpdl-1.53
ghostpdl-1.54
ghostpdl-10.*
ghostpdl-10.01.1-gse-10174
ghostpdl-10.02.0-test-base-001
ghostpdl-10.05.0-test-base-001
ghostpdl-8.*
ghostpdl-8.70
ghostpdl-8.71
ghostpdl-9.*
ghostpdl-9.00
ghostpdl-9.01
ghostpdl-9.02
ghostpdl-9.52-test-base-1
ghostpdl-9.52-test-base-3
ghostpdl-9.52-test-base-4
ghostpdl-9.54.0-test-base-0
ghostpdl-9.55-test-base-0
ghostpdl-9.56.0-test-base-0
ghostpdl-9.56.0-test-base-2
ghostpdl-9.56.0-test-base-3
ghostpdl-9.56.0-test-base-4
ghostpdl-9.56.0-test-base-5
ghostscript-6.*
ghostscript-6.0
ghostscript-6.01
ghostscript-6.20
ghostscript-6.21
ghostscript-6.22
ghostscript-6.23
ghostscript-6.30
ghostscript-6.31
ghostscript-6.32
ghostscript-6.50
ghostscript-6.60
ghostscript-6.61
ghostscript-6.62
ghostscript-6.63
ghostscript-6.64
ghostscript-7.*
ghostscript-7.00
ghostscript-7.02
ghostscript-7.03
ghostscript-7.04
ghostscript-7.20
ghostscript-7.21
ghostscript-7.22
ghostscript-7.30
ghostscript-7.31
ghostscript-7.32
ghostscript-7.33
ghostscript-8.*
ghostscript-8.00
ghostscript-8.01
ghostscript-8.10
ghostscript-8.11
ghostscript-8.12
ghostscript-8.13
ghostscript-8.14
ghostscript-8.15
ghostscript-8.30
ghostscript-8.31
ghostscript-8.32
ghostscript-8.33
ghostscript-8.50
ghostscript-8.51
ghostscript-8.52
ghostscript-8.53
ghostscript-8.56
ghostscript-8.57
ghostscript-8.60
ghostscript-8.61
ghostscript-8.62
ghostscript-8.63
ghostscript-8.64
ghostscript-8.70
ghostscript-8.71
ghostscript-9.*
ghostscript-9.01
ghostscript-9.02
jbig2dec-0.*
jbig2dec-0.14

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39919.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "305393621015670409414065145841442554734",
                "239732983865232904002593583924554111822",
                "77881441252370985866996222684578933495",
                "150728988227669549748412078396747417988",
                "139369699657578672416155712589810479655",
                "263227610100647875364897574580828041454",
                "30062800754376641575654399888605665918",
                "148550485105214349519108204478230351342",
                "209013882919373741414526516809907352723",
                "142418078663796278457048400302235852842",
                "201854491978180642697412375915342187551",
                "110332846198197084865785478293409017128",
                "257284505806104527113100397182780155790",
                "250378790091529030995621502470525666162",
                "185904196480304190715015237931261802876",
                "302280129440084736579762531051409376155"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-39919-da8e3e96",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/artifexsoftware/ghostpdl/commit/0a8bf88e39db07b0751a58d6ec1cf992073e4dc1",
        "target": {
            "file": "base/sjpx_openjpeg.c"
        }
    }
]
vanir_signatures_modified
"2026-09-17T08:08:34Z"

Git / github.com/artifexsoftware/ghostpdl-downloads

Affected ranges

Type
GIT
Repo
https://github.com/artifexsoftware/ghostpdl-downloads
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

10.*
10.03.1
9.*
9.21rc1
9.27
9.27rc1
9.54.0rc1
ghostpdl-9.*
ghostpdl-9.51
ghostpdl-9.51rc2
ghostpdl-9.53.0rc1
ghostpdl-9.53.0rc2
ghostpdl-9.55
Other
gpdf_alpha1
gpdf_alpha2
gpdf_beta1
gs1000
gs1000rc2
gs1001
gs10010
gs10010rc1
gs10010rc2
gs10011
gs10012
gs10020
gs10020rc1
gs10020rc2
gs10021
gs10030
gs10030rc1
gs10031
gs10040
gs10040rc1
gs10050
gs100501
gs10050rc1
gs10051
gs10060
gs10060rc1
gs10060rc2
gs10070
gs10070rc1
gs10071
gs10071rc1
gs10080rc1
gs918
gs919
gs920
gs920rc1
gs921
gs922
gs922rc1
gs922rc2
gs923
gs923rc1
gs924
gs924rc2
gs925
gs925rc1
gs926
gs927
gs928rc1
gs928rc2
gs928rc3
gs928rc4
gs950
gs951
gs951rc3
gs952
gs9530
gs9531
gs9532
gs9533
gs9540
gs9550
gs9550rc1
gs9560
gs9560rc1
gs9560rc2
gs9561
gs10.*
gs10.0.0rc1
gs10.06.0
gs10.07.0rc1
gs9.*
gs9.26rc1
gs9.27

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39919.json"