CVE-2026-62986: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in AcademySoftwareFoundation openexr
Description
A vulnerability in the PyOpenEXR Python bindings of the OpenEXR image file format library allows exposure of uninitialized heap memory when reading crafted deep scanline EXR files with layer-prefixed RGB channels. This occurs in versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13. The issue causes stale heap data to be returned in NumPy sample arrays, potentially exposing sensitive information. The flaw is fixed in versions 3.3.13 and 3.4.14.
CVSS v3.1
Score 4.3medium
Affected software
AcademySoftwareFoundation
openexr
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenEXR's PyOpenEXR Python bindings improperly handle deep scanline EXR files that use layer-prefixed RGB channels. When the default channel coalescing is enabled (separate_channels=False), the wrapper groups channels like left.R, left.G, and left.B into a single RGB sample array. However, the lane-offset calculation in PyPart::setDeepSliceData() only recognizes unprefixed channel names (G, B, A). Consequently, prefixed channels such as left.G and left.B are decoded into lane 0, leaving lanes 1 and 2 uninitialized. These uninitialized lanes are returned to Python, exposing stale heap data. Applications reading untrusted deep EXR files and processing the resulting NumPy arrays may inadvertently expose sensitive same-process heap contents and receive incorrect green and blue channel data. The vulnerability is addressed in OpenEXR versions 3.3.13 and 3.4.14.
Potential Impact
The vulnerability can lead to exposure of uninitialized heap memory contents to Python applications processing crafted deep EXR files, potentially leaking sensitive information. Additionally, the green and blue channel data returned may be incorrect, which could affect image processing results. There is no indication of integrity or availability impact. The CVSS score is 4.3 (medium severity), reflecting limited confidentiality impact with no required privileges and user interaction needed.
Mitigation Recommendations
This issue is fixed in OpenEXR versions 3.3.13 and 3.4.14. Users and developers should upgrade to these or later versions to remediate the vulnerability. Until then, avoid processing untrusted deep EXR files with the PyOpenEXR Python bindings using default channel coalescing. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-14T22:48:09.781Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8de143acd9273b4991a197
Added to database: 08/25/2026, 18:38:59 UTC
Last enriched: 09/10/2026, 17:39:29 UTC
Last updated: 10/09/2026, 18:48:21 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.