Heap Out-of-Bounds Write in OpenEXR Image Processing Software by Academy Software Foundation
CVE-2026-59187

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-59187?

OpenEXR, the widely-utilized implementation and specification for the EXR image format in the motion picture industry, is prone to a heap out-of-bounds write vulnerability. This issue arises during the processing of crafted deep scanline EXR images when using specific pixel conversion options, leading to mismanagement of sample buffer allocations. This security flaw affects several versions, including 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, and has been addressed in subsequent releases.

Affected Version(s)

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.