CVE-2026-39919
Reported by VulnCheck · Published September 15, 2026
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex Software | Ghostscript | 0 |
| artifex | ghostscript | 0 |
| Artifex Software | Ghostscript | 0, 0, 0 |
Timeline
- Sep 15, 2026 Coalition ESS Score
- Sep 15, 2026 CVE Published
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 24, 2026 CVE Updated
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Security Advisory
- Oct 6, 2026 EPSS Score
References
- Ghostscript 10.08.0 (gs10080) Release Notes release-notes
- Patch Commit patch
- Bugzilla Report issue-tracking
- third-party-advisory