VDB

CVE-2026-59189

CVE-2026-59189 PUBLISHED CVSS 7.1 HIGH

Reported by GitHub_M · Published August 25, 2026

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Affected Products

VendorProductVersions
AcademySoftwareFoundationopenexr< 3.2.11, >= 3.3.0, < 3.3.13, >= 3.4.0, < 3.4.14
alpineopenexr0, 0, 0
AcademySoftwareFoundationopenexr< 3.2.11, >= 3.3.0, < 3.3.13, >= 3.4.0, < 3.4.14

Timeline

  • Aug 25, 2026 Coalition ESS Score
  • Aug 25, 2026 CVE Published
  • Aug 26, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 5, 2026 EPSS Score
  • Sep 9, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›