Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenEXR — Vulnerabilities & Security Advisories 72

All 72 CVE vulnerabilities found in OpenEXR, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for OpenEXR, an open-source image file format library maintained by the OpenImageIO project. It collects reported vulnerabilities such as memory safety flaws, input validation errors, and integer overflows, covering advisories published from 2015 through the present. Readers can use this collection to track the vendor’s security advisory history, understand the prevalence of specific weakness classes, and review the product’s overall vulnerability landscape. The data supports risk assessment by highlighting recurring issue types and temporal trends in reported defects.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-59981 OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow CWE-125 7.1 High 2026-08-25
CVE-2026-68514 OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep images CWE-122 5.5 Medium 2026-08-25
CVE-2026-68515 OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union CWE-122 7.1 High 2026-08-25
CVE-2026-68513 OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision CWE-122 7.1 High 2026-08-25
CVE-2026-65979 OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) CWE-20 6.7 Medium 2026-08-25
CVE-2026-62986 OpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosure CWE-200 4.3 Medium 2026-08-25
CVE-2026-61555 OpenEXR: Empty multiView viewFromChannelName file crash CWE-125 5.5 Medium 2026-08-25
CVE-2026-59985 OpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32 CWE-125 5.5 Medium 2026-08-25
CVE-2026-59984 OpenEXR: Scratch buffer overflow decoding B44-compressed InputFile on ILP32 CWE-787 5.5 Medium 2026-08-25
CVE-2026-59983 OpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode on ILP32 CWE-125 5.5 Medium 2026-08-25
CVE-2026-59982 OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms CWE-190 7.1 High 2026-08-25
CVE-2026-59189 OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow origin CWE-125 7.1 High 2026-08-25
CVE-2026-59187 OpenEXR: exrmetrics deep pixelmode heap buffer overflow CWE-122 7.1 High 2026-08-25
CVE-2026-59186 OpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow on 32-bit (ILP32) builds CWE-122 7.1 High 2026-08-25
CVE-2026-59184 OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write CWE-416 7.1 High 2026-08-25
CVE-2026-59183 OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding CWE-190 5.5 Medium 2026-08-25
CVE-2026-55373 OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample counts CWE-190 6.2 Medium 2026-08-25
CVE-2026-55371 OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length CWE-20 6.9 Medium 2026-08-25
CVE-2026-55059 OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerability CWE-787 6.1 Medium 2026-08-25
CVE-2026-54920 OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize CWE-190 - - 2026-08-25
CVE-2026-53532 OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) CWE-617 7.1 High 2026-08-24
CVE-2026-68516 OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow CWE-787 6.5 Medium 2026-08-24
CVE-2026-45696 OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) CWE-122 - - 2026-06-18
CVE-2026-44663 OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow CWE-190 6.1 Medium 2026-06-18
CVE-2026-42217 OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`) CWE-190 8.1AI High AI 2026-05-07
CVE-2026-42216 OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion CWE-125 8.8 High 2026-05-07
CVE-2026-41142 OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API CWE-190 8.8 High 2026-05-07
CVE-2026-40250 OpenEXR has integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589) CWE-190 8.1AI High AI 2026-04-21
CVE-2026-40244 OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589) CWE-190 7.5AI High AI 2026-04-21
CVE-2026-39886 OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl() CWE-190 5.3 Medium 2026-04-21

All 72 known CVE vulnerabilities affecting OpenEXR with full Chinese analysis, references, and POCs where available.