{"id":"PYSEC-2026-2836","summary":"Out-of-bounds Read in OpenCV","details":"An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read in the function cv::predictOrdered\u003ccv::HaarEvaluator\u003e in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.","aliases":["CVE-2019-14491","GHSA-fm39-cw8h-3p63","PYSEC-2026-2797","PYSEC-2026-2818","PYSEC-2026-720"],"modified":"2026-07-13T16:43:43.678163290Z","published":"2026-07-09T16:49:35.914332Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14491"},{"type":"WEB","url":"https://github.com/opencv/opencv/issues/15125"},{"type":"PACKAGE","url":"https://github.com/opencv/opencv-python"},{"type":"WEB","url":"https://github.com/opencv/opencv/compare/33b765d...4a7ca5a"},{"type":"WEB","url":"https://github.com/opencv/opencv/compare/371bba8...ddbd10c"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPFLN6QAX6SUA4XR4NMKKXX26H3TYCVQ"},{"type":"PACKAGE","url":"https://pypi.org/project/opencv-python-headless"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fm39-cw8h-3p63"}],"affected":[{"package":{"name":"opencv-python-headless","ecosystem":"PyPI","purl":"pkg:pypi/opencv-python-headless"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.7.28"},{"introduced":"4.0.0.21"},{"fixed":"4.1.1.26"}]}],"versions":["3.4.3.18","3.4.4.19","3.4.5.20","3.4.6.27","4.0.0.21","4.0.1.24","4.1.0.25"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/opencv-python-headless/PYSEC-2026-2836.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}