SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59184

HIGH · CVSS 7.1 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects OpenEXR, specifically versions prior to 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, allowing crafted EXR files to trigger out-of-bounds or use-after-free writes via the TypedFlatImageChannel::row() function. This can lead to potential exploitation in tools, converters, and image-processing services that handle untrusted EXR files. Organizations utilizing these versions in their rendering or image processing workflows should prioritize updating to the patched versions (3.2.11, 3.3.13, or 3.4.14) to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59184
Severity
HIGH
CVSS
7.1
EPSS
0.22%

Original NVD Description

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.