{"id":"CVE-2026-59184","title":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry","summary":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dat…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","cwe":["CWE-416","CWE-787"],"published":"2026-08-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:07:31.353","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","references":[{"url":"https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","label":"security-advisories@github.com"},{"url":"https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","label":"security-advisories@github.com"},{"url":"https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","label":"security-advisories@github.com"},{"url":"https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59184.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59184"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523654"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59184"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00218,"epssPercentile":0.12483,"ingestedAt":"2026-09-09T21:22:45.552Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9"],"slug":"CVE-2026-59184","body":"## Overview\n\nOpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-19 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59184.json)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}