VulnSea

openexr vulnerabilities

CVEs whose affected-version data names the openexr package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

20 CVEsRSS

CVE-2026-59984Medium· 5.5PoC
4w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

TwilightAcademySoftwareFoundation · openexrEPSS 0.18%via NVD
CVE-2026-59985Medium· 5.5PoC
4w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

TwilightAcademySoftwareFoundation · openexrEPSS 0.18%via NVD
CVE-2026-61555Medium· 5.5
4w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. Th…

SunlitAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-42216Critical· 9.1PoC
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…

Abyssalopenexr · openexrEPSS 0.46%via NVD
CVE-2026-41142High· 8.8
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, the…

Twilightopenexr · openexrEPSS 0.44%via NVD
CVE-2026-34589Medium· 5.0
5mo ago

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

Sunlitopenexr · openexrEPSS 0.42%via OSV
CVE-2025-64182High· 7.8
5mo ago

OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()

OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()

Twilightopenexr · openexrEPSS 0.24%via OSV
CVE-2026-26981Medium· 6.5
5mo ago

OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

Sunlitopenexr · openexrEPSS 0.52%via OSV
CVE-2026-34588High· 8.6
5mo ago

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…

TwilightAcademySoftwareFoundation · openexrEPSS 0.48%via CVEORG
CVE-2025-64183High· 7.5
5mo ago

OpenEXR has use after free in PyObject_StealAttrString

OpenEXR has use after free in PyObject_StealAttrString

Twilightopenexr · openexrEPSS 0.30%via OSV
CVE-2025-64181High· 7.5
5mo ago

OpenEXR Makes Use of Uninitialized Memory

OpenEXR Makes Use of Uninitialized Memory

Twilightopenexr · openexrEPSS 0.38%via OSV
CVE-2026-34543High
5mo ago

OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)

OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)

Twilightopenexr · openexrEPSS 0.48%via OSV
CVE-2026-34544High
5mo ago

OpenEXR: integer overflow to OOB write in uncompress_b44_impl()

OpenEXR: integer overflow to OOB write in uncompress_b44_impl()

Twilightopenexr · openexrEPSS 0.24%via OSV
CVE-2026-27622High· 8.4
6mo ago

OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…

TwilightAcademySoftwareFoundation · openexrEPSS 0.20%via CVEORG
CVE-2025-48074Medium
1y ago

OpenEXR Out-Of-Memory via Unbounded File Header Values

OpenEXR Out-Of-Memory via Unbounded File Header Values

Sunlitopenexr · openexrEPSS 0.26%via OSV
CVE-2025-48073Medium
1y ago

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

Sunlitopenexr · openexrEPSS 0.20%via OSV
CVE-2025-48071High· 7.8
1y ago

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

Twilightopenexr · openexrEPSS 0.31%via OSV
CVE-2025-48072Medium
1y ago

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

Sunlitopenexr · openexrEPSS 0.49%via OSV
CVE-2017-9111High· 8.8
4y ago

OpenEXR invalid write

OpenEXR invalid write

Twilightopenexr · openexrEPSS 3.6%via OSV
CVE-2017-9112Medium· 6.5
4y ago

OpenEXR invalid read

OpenEXR invalid read

Sunlitopenexr · openexrEPSS 2.2%via OSV
openexr vulnerabilities (CVEs) · VulnSea