Out-of-Bounds Read Vulnerability in OpenEXR by Academy Software Foundation
CVE-2026-59983

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-59983?

A significant vulnerability has been identified in the OpenEXR library, which is crucial in handling the EXR image format commonly found in the motion picture industry. Certain versions of OpenEXR are susceptible to an out-of-bounds read when processing specially crafted uncompressed deep-tile EXR files. The flaw arises during the sample-count table size calculation, which can lead to unexpected behavior, potentially resulting in denial of service. Recommended versions to mitigate this issue include OpenEXR 3.2.11, 3.3.13, and 3.4.14.

Affected Version(s)

openexr < 3.2.11 < 3.2.11

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.