Heap Buffer Overflow in OpenEXR Python Bindings from Academy Software Foundation
CVE-2026-68514

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-68514?

The OpenEXR Python bindings have a vulnerability that allows for a heap buffer overflow when processing a specifically crafted deep scanline EXR file. This issue arises from the wrapper incorrectly handling literal and prefixed RGB channels, which leads to memory corruption and crashes during decoding. Users are encouraged to upgrade to versions 3.3.13 or 3.4.14 to mitigate this risk.

Affected Version(s)

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.