CVE-2022-38266

Executive Summary

Leptonica v1.79.0 is vulnerable to a crafted JPEG that triggers an arithmetic exception, causing a denial‑of‑service. The flaw is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2022-09-09T22:15:08.830 - Last Modified: 2026-09-14T14:10:44.773

Original Description: An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

"Love at first sight is easy to understand; its when two people have been looking at each other for a lifetime that it becomes a miracle."

— Amy Bloom
Source: NVD