Out-of-Bounds Read Vulnerability in OpenEXR Library Affecting Multiple Versions
CVE-2026-59981

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-59981?

The OpenEXR library, used widely within the motion picture industry for handling EXR image files, is susceptible to an out-of-bounds read vulnerability. This issue arises from the row() API function of the SampleCountChannel, which incorrectly handles data windows with non-zero origins. Specifically, when a deep image's data window features a large negative vertical origin, it may lead to address calculations that extend beyond allocated memory, resulting in possible crashes or exploitation through unauthorized memory access. Users are advised to upgrade to the fixed versions 3.2.11, 3.3.13, or 3.4.14 to mitigate these risks.

Affected Version(s)

openexr < 3.2.11 < 3.2.11

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.