CVE-2026-59187
Received
Received - Intake
Heap Out-of-Bounds Write in OpenEXR
Vulnerability report for CVE-2026-59187, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-25
Last updated on: 2026-08-25
Assigner: GitHub, Inc.
Description
Description
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| academysoftwarefoundation | openexr | From 3.3.0 (inc) to 3.3.13 (exc) |
| academysoftwarefoundation | openexr | From 3.4.0 (inc) to 3.4.14 (exc) |
| openexr | openexr | From 3.3.0 (inc) to 3.3.12 (inc) |
| openexr | openexr | From 3.4.0 (inc) to 3.4.13 (inc) |
| openexr | openexr | 3.3.13 |
| openexr | openexr | 3.4.14 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-122 | A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc(). |
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |