


Perceptive Security
SOC/SIEM Consultancy

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, …
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 21:01:54
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
OpenEXR, the reference implementation for the EXR image format widely used in the motion picture industry, contains a vulnerability in multiple versions. Affected versions include those before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. The flaw resides in the TypedDeepImageChannel::row() function, which can return an out-of-bounds pointer when processing a crafted deep EXR file with a nonzero dataWindow origin. The root cause is an API design issue where zero-based row access is combined with an absolute-coordinate-adjusted base pointer. Exploitation of this vulnerability can lead to application crashes or limited information disclosure. Fixed versions are 3.2.11, 3.3.13, and 3.4.14. Multiple commits have been published to the OpenEXR GitHub repository addressing this issue. A GitHub Security Advisory (GHSA-6662-fq6f-93mp) has also been published.
Technical details
Mitigation steps:
Affected products:
OpenEXR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59982
https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1
https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c
https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
