Denial of Service Vulnerability in OpenEXR by Academy Software Foundation
CVE-2026-68516
6.5MEDIUM
What is CVE-2026-68516?
OpenEXR, a widely used image format implementation in the motion picture industry, is susceptible to a Denial of Service condition when processing crafted HTJ2K-compressed EXR files. Specifically, when the JPEG 2000 SIZ fields are configured such that the first tile does not intersect the visible image, it can lead to an invalid tile and codeblock geometry in the embedded OpenJPH AVX2 decoder, resulting in crashes during decoding. This vulnerability is mitigated in version 3.4.14, which introduces checks to prevent such malformed inputs from causing disruptions.
Affected Version(s)
openexr >= 3.4.0, < 3.4.14
