CVE-2023-39329: Uclouvain Openjpeg

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

Affected products

  • Uclouvain Openjpeg: version 2.0 only; affected versions not specified; version 2.5.0 only

Published 2024-07-13. Last modified 2026-09-21.