


Perceptive Security
SOC/SIEM Consultancy

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 th…
Published:
25 August 2026 at 00:00:00
Alert date:
25 August 2026 at 20:05:56
Source:
nvd.nist.gov
Supply Chain & Dependencies, Data Breach & Exfiltration
A heap out-of-bounds read vulnerability exists in OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12. The flaw is in the TypedDeepImageChannel<T>::row() API, which can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin. The root cause is a conflict between two coordinate models in ImfDeepImageChannel: at(x, y) uses absolute coordinates while row(r) is documented as 0-based logical access. For non-zero dataWindow.min values, row(0) points outside the _sampleListPointers allocation, causing a heap out-of-bounds read and potential crash. Under a controlled heap layout, this could lead to information disclosure. The vulnerability affects the EXR image format library widely used in the motion picture industry. Fixes are available in versions 3.3.13 and 3.4.13.
Technical details
Mitigation steps:
Affected products:
OpenEXRUtil 3.3.0-3.3.12
OpenEXRUtil 3.4.0-3.4.12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59189
https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1
https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c
https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
