Out-of-bounds Vulnerability in OpenEXR Image Processing Software from Academy Software Foundation
CVE-2026-59982

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-59982?

The OpenEXR image processing software, widely adopted in the film industry, contains an out-of-bounds vulnerability that can be exploited when processing deep EXR files with specific configurations. This flaw specifically arises in the TypedDeepImageChannel::row() method, where the combination of a zero-based row access pattern and an absolute-coordinate-adjusted base pointer can lead to a crash or potentially expose sensitive information. Affected versions include those prior to 3.2.11 and certain releases in the 3.3 and 3.4 series. Mitigation is available in subsequent updates.

Affected Version(s)

openexr >= 3.1.0, < 3.2.11 < 3.1.0, 3.2.11

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.