{"id":"CVE-2019-19624","aliases":["GHSA-jggw-2q6g-c3m6","PYSEC-2026-2800","PYSEC-2026-2824","PYSEC-2026-2839","PYSEC-2026-723"],"url":"https://o3.security/vulnerability/CVE-2019-19624","summary":"Out-of-bounds Read in OpenCV","details":"An out-of-bounds read was discovered in OpenCV before 4.1.1 (OpenCV-Python before 4.1.0.25). Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.","published":"2019-12-06T15:15:10.330Z","modified":"2026-07-13T16:42:38.267494498Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"opencv-python","fixedVersion":"4.1.0.25"},{"ecosystem":"PyPI","name":"opencv-python-headless","fixedVersion":"4.1.0.25"},{"ecosystem":"PyPI","name":"opencv-contrib-python","fixedVersion":"4.1.0.25"},{"ecosystem":"PyPI","name":"opencv-contrib-python-headless","fixedVersion":"4.1.0.25"}],"fix":{"url":"https://github.com/opencv/opencv/commit/d1615ba11a93062b1429fce9f0f638d1572d3418","label":"opencv/opencv@d1615ba"},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2019-19624"},{"type":"REPORT","url":"https://github.com/opencv/opencv/issues/14554"},{"type":"FIX","url":"https://github.com/opencv/opencv/commit/d1615ba11a93062b1429fce9f0f638d1572d3418"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19624"},{"type":"PACKAGE","url":"https://github.com/opencv/opencv-python"},{"type":"WEB","url":"https://github.com/opencv/opencv-python/releases/tag/25"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T16:42:38.267494498Z"}}