CVE-2026-51808
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp
Published 2026-07-14. Last modified 2026-07-15.