EIP-2026-103623

PRE-CVE

pdfium - opj_jp2_apply_pclr 'libopenjpeg' Heap Out-of-Bounds Read

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103623. PoCs published by Google Security Research.

AI-analyzed exploit summary This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (libopenjpeg20) during PDF fuzzing. The report details an out-of-bounds read in the `opj_jp2_apply_pclr` function, leading to a potential denial-of-service (DoS) condition.

Description

pdfium - opj_jp2_apply_pclr 'libopenjpeg' Heap Out-of-Bounds Read

Exploits (1)

exploitdb WRITEUP VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39321

This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (libopenjpeg20) during PDF fuzzing. The report details an out-of-bounds read in the `opj_jp2_apply_pclr` function, leading to a potential denial-of-service (DoS) condition.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: PDFium (Chrome PDF renderer) with OpenJPEG 2.0
No auth needed
Prerequisites: A maliciously crafted PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026