JLSEC-2026-1267

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1267.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1267.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1267
Upstream
  • EUVD-2026-22030
  • GHSA-6jfp-5ggc-pgmx
Published
2026-08-12T16:30:03.817Z
Modified
2026-08-12T16:58:44.023790730Z
Severity
  • 1.7 (Low) CVSS_V2 - AV:L/AC:L/Au:S/C:N/I:N/A:P CVSS Calculator
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function...
Details

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

Database specific
{
    "sources": [
        {
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6192",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6192",
            "imported": "2026-08-12T15:00:20.298Z",
            "published": "2026-04-13T17:16:32.333Z",
            "id": "CVE-2026-6192",
            "database_specific": {
                "status": "Deferred"
            },
            "modified": "2026-06-17T11:00:27.637Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-6jfp-5ggc-pgmx",
            "modified": "2026-05-21T18:33:06Z",
            "imported": "2026-08-12T15:00:05.567Z",
            "published": "2026-04-13T18:30:42Z",
            "id": "GHSA-6jfp-5ggc-pgmx",
            "url": "https://api.github.com/advisories/GHSA-6jfp-5ggc-pgmx"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22030",
            "modified": "2026-05-21T15:04:22Z",
            "imported": "2026-08-12T15:00:04.079Z",
            "published": "2026-04-13T16:45:11Z",
            "id": "EUVD-2026-22030",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-22030"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / OpenJpeg_jll

Package

Name
OpenJpeg_jll
Purl
pkg:julia/OpenJpeg_jll?uuid=643b3616-a352-519d-856d-80112ee9badc

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1267.json"