OpenHTJ2K Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in OpenHTJ2K versions through 0.18.4. This vulnerability allows an attacker to execute arbitrary code by exploiting the j2k_precinct_subband::parse_packet_header() function in the coding_units.cpp file.

Impact

Exploitation of this vulnerability leads to a heap buffer overflow, allowing for out-of-bounds writes that can corrupt adjacent heap memory. This vulnerability also creates a potential server-side heap information leak.

Reproduction

The vulnerability can be reproduced by sending crafted J2K or JP2 files that exploit the buffer overflow in the PPM packet header parsing. This can be done through the JPIP server's startup codestream load or by using the public decoder entry points.

Remediation

Users should upgrade to OpenHTJ2K version 0.19.0, which includes the necessary security fix.

Added: Jul 15, 2026, 3:30 AM
Updated: Jul 15, 2026, 3:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.8
remediation
0.0
relevance
9.3
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.