OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
{
"license": "CC-BY-4.0",
"sources": [
{
"published": "2025-08-05T15:15:32Z",
"imported": "2026-07-17T22:07:25.838Z",
"database_specific": {
"status": "Modified"
},
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-54874",
"modified": "2026-06-17T09:40:50.743Z",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54874",
"id": "CVE-2025-54874"
},
{
"published": "2025-08-05T14:33:17Z",
"imported": "2026-07-17T22:07:26.365Z",
"id": "EUVD-2025-23631",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-23631",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23631",
"modified": "2026-02-26T17:49:57Z"
}
]
}