JLSEC-2026-535

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-535.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-535.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-535
Upstream
Published
2026-05-26T19:31:24.313Z
Modified
2026-05-26T19:45:05.113405501Z
Summary
[none]
Details

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "id": "CVE-2020-27814",
            "imported": "2026-05-25T01:08:37.494Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27814",
            "modified": "2024-11-21T05:21:51.817Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2020-27814",
            "published": "2021-01-26T18:15:46.613Z",
            "database_specific": {
                "status": "Modified"
            }
        }
    ]
}
References

Affected packages

Julia / OpenJpeg_jll

Package

Name
OpenJpeg_jll
Purl
pkg:julia/OpenJpeg_jll?uuid=643b3616-a352-519d-856d-80112ee9badc

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-535.json"