OpenEXR is vulnerable to Information Disclosure
33
Low Risk
OpenEXR's NO_COMPRESSION scanline path, embedded in the PyPI OpenEXR extension, accepts a chunk shorter than the declared unpacked pixel data. The short chunk leaves part of the destination buffer uninitialized, and those bytes can be copied into caller-visible pixels during decode through the Python bindings. The fix rejects undersized compressed or raw streams before reconstructing full channel rows.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted uncompressed scanline EXR files through the OpenEXR Python bindings.
OpenEXR is vulnerable to Information Disclosure in versions 3.2.3 - 3.4.13.
Upgrade the OpenEXR library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant