OpenEXR is vulnerable to Denial of Service
55
Medium Risk
OpenEXRCore's planar HTJ2K decoder, shipped inside the PyPI OpenEXR extension module, computes a decode loop endpoint by adding an unsigned image height to a signed chunk origin. For a file with a negative data-window Y origin and vertical subsampling, mixed arithmetic wraps the endpoint so the decoder stays CPU-bound until externally terminated. The fix computes the loop endpoint entirely in signed 64-bit arithmetic.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted HTJ2K-compressed EXR files through the OpenEXR Python bindings.
OpenEXR is vulnerable to Denial of Service in versions 3.4.0 - 3.4.13.
Upgrade the OpenEXR library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant