Denial of Service Vulnerability in OpenEXR by Academy Software Foundation
CVE-2026-68516

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-68516?

OpenEXR, a widely used image format implementation in the motion picture industry, is susceptible to a Denial of Service condition when processing crafted HTJ2K-compressed EXR files. Specifically, when the JPEG 2000 SIZ fields are configured such that the first tile does not intersect the visible image, it can lead to an invalid tile and codeblock geometry in the embedded OpenJPH AVX2 decoder, resulting in crashes during decoding. This vulnerability is mitigated in version 3.4.14, which introduces checks to prevent such malformed inputs from causing disruptions.

Affected Version(s)

openexr >= 3.4.0, < 3.4.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.