Heap-Based Buffer Overflow in Ghostscript's JPEG 2000 Output Adapter
CVE-2026-39919

9.3CRITICAL

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-39919?

Ghostscript prior to version 10.08.0 has a vulnerability in its JPEG 2000 output adapter, where a heap-based buffer overflow can occur. Attackers can exploit this by crafting a PDF that includes a JPEG 2000 image with mismatched subsampling factors. The processing of these images leads to memory corruption, as the system allocates an incorrect-sized row buffer and writes beyond its boundaries. This overflow can corrupt the chunk-allocator's metadata, potentially allowing code execution by the attacker.

Affected Version(s)

Ghostscript 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas, Wordfence
Wordfence Argus
.