CVE-2025-53644

9.8 CRITICAL
Published: July 17, 2025 Modified: October 17, 2025

Description

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/opencv/opencv/issues/27271
Source: security-advisories@github.com
Issue Tracking
https://github.com/opencv/opencv/releases/tag/4.12.0
Source: security-advisories@github.com
Release Notes
https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/
Source: security-advisories@github.com
Exploit Third Party Advisory

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
0.1%
20th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

opencv