OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public imagespec while the decod
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AcademySoftwareFoundation | OpenImageIO | < 3.0.21.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63638 | 8.3 HIGH | OpenImageIO: Cineon invalid bit depth heap out-of-bounds write |
| CVE-2026-63422 | 7.8 HIGH | OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write |
| CVE-2026-67549 | 7.6 HIGH | OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write |
| CVE-2026-59156 | 6.5 MEDIUM | OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow |
| CVE-2026-59956 | 6.1 MEDIUM | OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set |
| CVE-2026-59181 | 6.1 MEDIUM | OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElem |
| CVE-2026-63420 | 5.5 MEDIUM | OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row` |
| CVE-2026-63635 | 5.5 MEDIUM | OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocati |
| CVE-2026-65969 | 5.5 MEDIUM | OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV |
| CVE-2026-65970 | 5.3 MEDIUM | OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_s |
No comments yet