OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-pac
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AcademySoftwareFoundation | OpenImageIO | < 3.1.16.0 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AcademySoftwareFoundation | OpenImageIO | < 3.1.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63638 | 8.3 HIGH | OpenImageIO: Cineon invalid bit depth heap out-of-bounds write |
| CVE-2026-63422 | 7.8 HIGH | OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write |
| CVE-2026-63419 | 7.8 HIGH | OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer |
| CVE-2026-59156 | 6.5 MEDIUM | OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow |
| CVE-2026-59956 | 6.1 MEDIUM | OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set |
| CVE-2026-59181 | 6.1 MEDIUM | OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElem |
| CVE-2026-63420 | 5.5 MEDIUM | OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row` |
| CVE-2026-63635 | 5.5 MEDIUM | OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocati |
| CVE-2026-65969 | 5.5 MEDIUM | OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV |
| CVE-2026-65970 | 5.3 MEDIUM | OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_s |
No comments yet