logo

CVE-2026-39919: Ghostscript JPEG 2000 Heap Buffer Overflow

ID: 730f001d-ee99-5917-a950-2775f86847ed

STIX ID: report--730f001d-ee99-5917-a950-2775f86847ed

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

...
...

A critical heap-based buffer overflow (CVE-2026-39919, CVSS 3.1 9.8) exists in Ghostscript's JPEG 2000 output adapter (base/sjpx_openjpeg.c) and can be triggered by a crafted PDF containing a JPEG 2000 image with mismatched subsampling factors; the bug can corrupt heap allocator metadata and potentially be leveraged for code execution. Ghostscript 10.08.0 (2026-09-08) contains the fix; the report recommends updating, checking downstream vendored copies, isolating processing of untrusted PDFs, and monitoring for crashes and anomalous behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.