{"id":"PYSEC-2026-721","summary":"Out-of-bounds Read and Out-of-bounds Write in OpenCV","details":"An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.","aliases":["CVE-2019-14492","GHSA-fw99-f933-rgh8","PYSEC-2026-2798","PYSEC-2026-2821","PYSEC-2026-2837"],"modified":"2026-07-13T16:57:16.873713760Z","published":"2026-07-02T14:13:12.762657Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14492"},{"type":"WEB","url":"https://github.com/opencv/opencv/issues/15124"},{"type":"PACKAGE","url":"https://github.com/opencv/opencv-python"},{"type":"WEB","url":"https://github.com/opencv/opencv/compare/33b765d...4a7ca5a"},{"type":"WEB","url":"https://github.com/opencv/opencv/compare/371bba8...ddbd10c"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00025.html"},{"type":"PACKAGE","url":"https://pypi.org/project/opencv-contrib-python-headless"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fw99-f933-rgh8"}],"affected":[{"package":{"name":"opencv-contrib-python-headless","ecosystem":"PyPI","purl":"pkg:pypi/opencv-contrib-python-headless"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.7.28"},{"introduced":"4.0.0.21"},{"fixed":"4.1.1.26"}]}],"versions":["3.4.0.14","3.4.1.15","3.4.2.17","3.4.3.18","3.4.4.19","3.4.5.20","3.4.6.27","4.0.0.21","4.0.1.23","4.0.1.24","4.1.0.25"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/opencv-contrib-python-headless/PYSEC-2026-721.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}