Intel

AIKIDO-2026-10815

OpenEXR is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2026-42216 Published May 14, 2026

75

High Risk

This Affects:

PYTHONOpenEXR
3.0.0 - 3.2.8
Fixed in 3.2.9
3.3.0 - 3.3.10
Fixed in 3.3.11
3.4.0 - 3.4.10
Fixed in 3.4.11
Are you affected? Scan for Free

TL;DR

Affected versions of openexr contain an out-of-bounds read vulnerability in IDManifest::init() when processing prefix-compressed strings. A specially crafted .exr file can trigger reads beyond the bounds of a heap-allocated string buffer, potentially leading to information disclosure or denial of service through application crashes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

OpenEXR is vulnerable to Out-of-bounds Read in versions 3.0.0 - 3.2.8, 3.3.0 - 3.3.10 and 3.4.0 - 3.4.10.

How to fix this

Upgrade the OpenEXR library to a patch version.