Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenEXR — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in OpenEXR, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with OpenEXR, an open-source image file format developed by Industrial Light & Magic, categorized under software weakness types. It aggregates a comprehensive collection of vulnerability records affecting the OpenEXR ecosystem, covering data ranging from early discoveries up to the present day. Users can utilize this resource to track vendor advisories related to the library, gain a deeper understanding of specific weakness classes and their impacts on image processing workflows, and look up the complete vulnerability history for various versions of the product. The data includes details on how flaws were discovered, their severity ratings, and the corresponding remediation efforts provided by the maintainers. By centralizing this information, the page serves as a reference for developers, security researchers, and system administrators who need to assess the risk posture of applications relying on OpenEXR. The entries are organized to facilitate easy navigation, allowing users to filter results by date, severity, or type of flaw. This structured approach helps in identifying patterns in how vulnerabilities arise within the codebase and how quickly they are patched. It is important to note that while this page provides historical context and technical details, it does not replace official security bulletins or real-time threat intelligence feeds. Users are encouraged to cross-reference this data with official vendor announcements for the most current status of any reported issues. The goal is to provide transparency and clarity regarding the security landscape of the OpenEXR project.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-45696 OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) CWE-122--2026-06-18
CVE-2026-44663 OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow CWE-190 6.1 Medium2026-06-18
CVE-2026-42217 OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`) CWE-190 8.1AIHighAI2026-05-07
CVE-2026-42216 OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion CWE-125 9.1AICriticalAI2026-05-07
CVE-2026-41142 OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API CWE-190 8.8 High2026-05-07
CVE-2026-40250 OpenEXR has integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589) CWE-190 8.1AIHighAI2026-04-21
CVE-2026-40244 OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589) CWE-190 7.5AIHighAI2026-04-21
CVE-2026-39886 OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl() CWE-190 5.3 Medium2026-04-21
CVE-2026-34589 OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write CWE-190 9.1 -2026-04-06
CVE-2026-34588 OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write CWE-125 6.8 -2026-04-06
CVE-2026-34380 OpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompression CWE-190 5.9 Medium2026-04-06
CVE-2026-34379 OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression) CWE-704 7.1 High2026-04-06
CVE-2026-34378 OpenEXR has a signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x CWE-190 6.5 Medium2026-04-06
CVE-2026-34543 OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl) CWE-908 5.5AIMediumAI2026-04-01
CVE-2026-34544 OpenEXR: integer overflow to OOB write in uncompress_b44_impl() CWE-190 8.8AIHighAI2026-04-01
CVE-2026-34545 OpenEXR: integer overflow lead to OOB in HTJ2K decoder CWE-122 9.6AICriticalAI2026-04-01
CVE-2026-27622 OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write CWE-787 7.7AIHighAI2026-03-03
CVE-2026-26981 OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp CWE-195 6.5 Medium2026-02-24
CVE-2025-12840 Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8AIHighAI2025-12-23
CVE-2025-12839 Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8AIHighAI2025-12-23
CVE-2025-12495 Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8AIHighAI2025-12-23
CVE-2025-64183 OpenEXR has use after free in PyObject_StealAttrString CWE-416 9.1 -2025-11-10
CVE-2025-64182 OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel() CWE-120 7.8 -2025-11-10
CVE-2025-64181 OpenEXR Makes Use of Uninitialized Memory CWE-457 9.1 -2025-11-10
CVE-2025-48074 OpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory Errors CWE-770 6.5 -2025-08-01
CVE-2025-48073 OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode CWE-476 7.5AIHighAI2025-07-31
CVE-2025-48072 OpenEXR's Inaccurate Pointer Arithmetic can Cause an Out of Bounds Heap CWE-125 7.8AIHighAI2025-07-31
CVE-2025-48071 OpenEXR's Forged Unpacked Size can Lead to Heap-Based Buffer Overflow in Deep Scanline Parsing CWE-122 7.8AIHighAI2025-07-31
CVE-2023-5841 OpenEXR Heap Overflow in Scanline Deep Data Parsing CWE-122 8.8 -2024-02-01
CVE-2021-20298 ILM OpenEXR 缓冲区错误漏洞 CWE-400 7.5 -2022-08-23

All 50 known CVE vulnerabilities affecting OpenEXR with full Chinese analysis, references, and POCs where available.