OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opjjp2readheader may lead to OOB heap memory write when the data stream pstream is too short and p_image is not initialized.
{
"sources": [
{
"imported": "2026-05-25T01:08:38.684Z",
"id": "CVE-2025-54874",
"modified": "2025-09-26T22:15:33.920Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-54874",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54874",
"database_specific": {
"status": "Modified"
},
"published": "2025-08-05T15:15:32Z"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23631",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-23631",
"id": "EUVD-2025-23631",
"imported": "2026-05-25T01:08:40.996Z",
"modified": "2026-02-26T17:49:57Z",
"published": "2025-08-05T14:33:17Z"
}
],
"license": "CC-BY-4.0"
}