{"id":"CVE-2019-14492","aliases":["GHSA-fw99-f933-rgh8","PYSEC-2026-2798","PYSEC-2026-2821","PYSEC-2026-2837","PYSEC-2026-721"],"url":"https://o3.security/vulnerability/CVE-2019-14492","summary":"Out-of-bounds Read and Out-of-bounds Write in OpenCV","details":"An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.","published":"2019-08-01T17:15:13.530Z","modified":"2026-07-13T16:42:42.959336096Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"opencv-python","fixedVersion":"3.4.7.28"},{"ecosystem":"PyPI","name":"opencv-python","fixedVersion":"4.1.1.26"},{"ecosystem":"PyPI","name":"opencv-python-headless","fixedVersion":"3.4.7.28"},{"ecosystem":"PyPI","name":"opencv-python-headless","fixedVersion":"4.1.1.26"},{"ecosystem":"PyPI","name":"opencv-contrib-python","fixedVersion":"3.4.7.28"},{"ecosystem":"PyPI","name":"opencv-contrib-python","fixedVersion":"4.1.1.26"},{"ecosystem":"PyPI","name":"opencv-contrib-python-headless","fixedVersion":"3.4.7.28"},{"ecosystem":"PyPI","name":"opencv-contrib-python-headless","fixedVersion":"4.1.1.26"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00025.html"},{"type":"ADVISORY","url":"https://github.com/opencv/opencv/compare/33b765d...4a7ca5a"},{"type":"ADVISORY","url":"https://github.com/opencv/opencv/compare/371bba8...ddbd10c"},{"type":"EVIDENCE","url":"https://github.com/opencv/opencv/issues/15124"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14492"},{"type":"PACKAGE","url":"https://github.com/opencv/opencv-python"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T16:42:42.959336096Z"}}