CVE-2026-39919
Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter
Description
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
In plain language
AI Act nowGhostscript versions earlier than 10.08.0 can be taken over through a malicious PDF, so small businesses using it should upgrade promptly.
Unauthenticated network-reachable remote code execution in Ghostscript through a heap buffer overflow triggered by a crafted PDF containing a JPEG 2000 image.
What to do now
- Check whether your systems or applications use Ghostscript and confirm the installed version.
- Upgrade Ghostscript to version 10.08.0 or later.
- Until upgraded, prevent untrusted PDF files from being processed by Ghostscript and isolate any necessary document-processing service.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-39919 and every CVE in our database. Create a free account — no credit card required.
Create Free Account