CVE-2025-53644

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opencv:opencv:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-17 18:15

Updated : 2025-10-17 19:18


NVD link : CVE-2025-53644

Mitre link : CVE-2025-53644

CVE.ORG link : CVE-2025-53644


JSON object : View

Products Affected

opencv

  • opencv
CWE
CWE-457

Use of Uninitialized Variable