Heap Write Overflow in OpenEXR Image File Format by Academy Software Foundation
CVE-2026-34545

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34545?

A vulnerability exists in OpenEXR, an image storage format widely used in the motion picture industry. Specifically, versions 3.4.0 to prior to 3.4.7 are susceptible to a heap write overflow when decoding specially crafted .exr files that utilize HTJ2K compression with a channel width of 32768. Attackers can exploit this by manipulating the EXR file, allowing them to write controlled data beyond the designated output heap buffer. This condition can result in arbitrary code execution on affected systems. The issue has been remedied in version 3.4.7.

Affected Version(s)

openexr >= 3.4.0, < 3.4.7

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.