PT-2025-52452 · Unknown+2 · Ai/Djl/Opencv/Extendedopencvimage+2
Xzzz111
·
Published
2025-12-19
·
Updated
2026-01-02
·
CVE-2025-66909
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Turms AI-Serving module versions prior to v0.10.0
Description
The software contains an image decompression bomb denial of service issue. The
ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java uses OpenCV’s imread() function to load images without validating dimensions or pixel count before decompression. A crafted compressed image file (e.g., PNG) can expand to gigabytes of memory when loaded, causing memory exhaustion, an OutOfMemoryError, and service crash. No authentication is required if the OCR service is publicly accessible.Recommendations
Versions prior to v0.10.0 should be updated.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencv
Turms
Ai/Djl/Opencv/Extendedopencvimage