Intel

AIKIDO-2026-630697

AcademySoftwareFoundation.openexr is vulnerable to Denial of Service

Denial of ServiceCVE-2026-61555 Published Aug 10, 2026

55

Medium Risk

This Affects:

C++AcademySoftwareFoundation.openexr
3.3.0 - 3.3.12
Fixed in 3.3.13
3.4.0 - 3.4.13
Fixed in 3.4.14
Are you affected? Scan for Free

TL;DR

An empty multiView attribute in a crafted EXR file can make viewFromChannelName() crash while resolving channel-to-view mappings. Applications that open untrusted EXR files and exercise multi-view channel naming therefore suffer a denial of service. The fix rejects empty multiView attributes before view resolution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you open untrusted EXR files that can carry a multiView attribute.

Background info

AcademySoftwareFoundation.openexr is vulnerable to Denial of Service in versions 3.3.0 - 3.3.12 and 3.4.0 - 3.4.13.

How to fix this

Upgrade the AcademySoftwareFoundation.openexr library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform