CVE-2025-54874 is a critical out-of-bounds heap memory write vulnerability affecting OpenJPEG versions 2.5.1 through 2.5.3. An unauthenticated attacker can trigger this flaw remotely by providing a malformed data stream during the opj_jp2_read_header function call, leading to complete compromise of confidentiality, integrity, and availability. Despite its critical severity (CVSS 9.8), there is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.3CPE matchmatch criteria | cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.