On October 9, 2026, Stuart Henderson posted to the oss-sec mailing list an advisory about OpenJPEG, an open-source library for encoding and decoding JPEG 2000 images. According to the post, a heap overflow was corrected in a commit on the repository's main branch, but the flaw remains in releases 2.5.3 and 2.5.4. The post links the correction commit to the project repository, and reading the original source is the only way to confirm technical details such as the affected function and the input vector.
The text also states that the repository should be considered unmaintained. According to the quoted passage, commits may appear from time to time depending on contributor interest and availability, but at present no contributor feels responsible for regularly reviewing tickets or pull requests. This matters because a fix on the main branch does not mean a released version with the fix is available.
For anyone who uses OpenJPEG indirectly, through libraries, conversion tools, or document and image pipelines, the practical point is to check the installed version and whether each component supplier has shipped the correction. Rota Nacional does not patch third-party libraries or guarantee that this dependency is current in customer systems, and this item does not describe any platform capability relating to this vulnerability.