OpenSlide C Library Vulnerability in Ventana BIF File Parsing
CVE-2026-48977

7.7HIGH

Key Information:

Vendor

Openslide

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-48977?

The OpenSlide C library, utilized for reading whole slide images, contains a vulnerability in its parse_level0_xml() function. This issue arises due to the handling of nonpositive row or column tile counts from a specially crafted Ventana BIF file. The presence of invalid counts allows attackers to control relative memory offsets, which can lead to the execution of arbitrary code and crashes across all supported platforms and configurations. The vulnerability is addressed in version 4.0.1, highlighting the importance of updating to this release.

Affected Version(s)

openslide >= 3.4.1, < 4.0.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.