opencv / opencv/opencv-python

Security Risk: av-4.11.0.86 includes vulnerable libgfortran version (CVE-2014-5044)

Open
#1,101 1 comment 0 reactions 1 assignee View on GitHub

@asmorkalov is already working on this.

Since May 23, 2025.

Dominant language
Python
Stars
5.4k
Forks
1k
Avg merge
22h 17m
Merged PRs (30d)
3

Description

Hi maintainers,
I’ve detected that the PyPI package opencv-python-4.11.0.86 includes a binary dependency (opencv_python.libs/libgfortran-91cc3cb1.so.3.0.0), which is vulnerable to CVE-2014-5044.

CVE Details:

Recommended Action:

Please consider upgrade libgfortran to 4.8 or later to mitigate the vulnerability. This will help downstream users avoid potential security issues caused by the bundled vulnerable binary.

Thanks!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.