Heap Out-of-Bounds Read Vulnerability in OpenEXR Product by Academy Software Foundation
CVE-2026-59985

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-59985?

OpenEXR, the reference implementation for the EXR image format utilized in the motion picture industry, is affected by a heap out-of-bounds read vulnerability. This issue can be triggered when a specially crafted RLE-compressed EXR file causes miscalculation of the unpacked size during allocation, leading to buffer over-read. The vulnerability spans several versions of OpenEXR and can result in denial of service. Mitigation is available in the latest releases, which rectify the size allocation oversight.

Affected Version(s)

openexr >= 3.2.0, < 3.2.11 < 3.2.0, 3.2.11

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.