CVE-2026-48977
CVE-2026-48977 is a high-severity vulnerability with a CVSS 4.0 base score of 7.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-123.
Key facts
- Severity: High (CVSS 4.0 base score 7.7)
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-123
- Published:
- Last modified:
Description
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and allow arbitrary values to be written at those offsets, affecting all supported platforms and configurations and resulting in a crash or potential arbitrary code execution. This issue is fixed in version 4.0.1.
Frequently asked questions
- What is CVE-2026-48977?
- OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and allow arbitrary values to be written at those offsets, affecting all supported platforms and configurations and resulting in a crash or potential arbitrary code execution. This issue is fixed in version 4.0.1.
- How severe is CVE-2026-48977?
- CVE-2026-48977 has a CVSS 4.0 base score of 7.7, rated high severity.
- Is CVE-2026-48977 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-48977?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-48977 published?
- CVE-2026-48977 was published on 2026-09-17 and last updated on 2026-09-23.
References
- https://github.com/openslide/openslide/commit/2be88bd782d9fff46de8e56a99baca523e7917b3
- https://github.com/openslide/openslide/pull/751
- https://github.com/openslide/openslide/releases/tag/v4.0.1
- https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc
Other CWE-123 vulnerabilities
- CVE-2025-69809 — Critical (CVSS 9.8): A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values…
- CVE-2022-38143 — Critical (CVSS 9.8): A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A…
- CVE-2021-38449 — Critical (CVSS 9.8): Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these…
- CVE-2015-8271 — Critical (CVSS 9.8): The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
- CVE-2026-30121 — Critical (CVSS 9.1): remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
- CVE-2026-81579 — High (CVSS 8.8): In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for…