openexr vulnerabilities
CVEs whose affected-version data names the openexr package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
20 CVEsRSS
CVE-2026-59984Medium· 5.5PoCOpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…
CVE-2026-59985Medium· 5.5PoCOpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…
CVE-2026-61555Medium· 5.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. Th…
CVE-2026-42216Critical· 9.1PoCOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…
CVE-2026-41142High· 8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, the…
CVE-2026-34589Medium· 5.0OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
CVE-2025-64182High· 7.8OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
CVE-2026-26981Medium· 6.5OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
CVE-2026-34588High· 8.6OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…
CVE-2025-64183High· 7.5OpenEXR has use after free in PyObject_StealAttrString
OpenEXR has use after free in PyObject_StealAttrString
CVE-2025-64181High· 7.5OpenEXR Makes Use of Uninitialized Memory
OpenEXR Makes Use of Uninitialized Memory
CVE-2026-34543HighOpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
CVE-2026-34544HighOpenEXR: integer overflow to OOB write in uncompress_b44_impl()
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
CVE-2026-27622High· 8.4OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…
CVE-2025-48074MediumOpenEXR Out-Of-Memory via Unbounded File Header Values
OpenEXR Out-Of-Memory via Unbounded File Header Values
CVE-2025-48073MediumOpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
CVE-2025-48071High· 7.8OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
CVE-2025-48072MediumOpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
CVE-2017-9111High· 8.8OpenEXR invalid write
OpenEXR invalid write
CVE-2017-9112Medium· 6.5OpenEXR invalid read
OpenEXR invalid read