CVE-2026-63635: CWE-125: Out-of-bounds Read in AcademySoftwareFoundation OpenImageIO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
AI Analysis
Technical Summary
OpenImageIO versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1 contain an out-of-bounds read vulnerability (CWE-125) in the PSD input handling code. When a specially crafted PSD file with an invalid color_mode is processed with oiio:rawcolor or psd:rawdata enabled, the PSDInput::setup() function uses the attacker-controlled color_mode value to index fixed color-mode tables improperly. This results in a global out-of-bounds read and potentially bogus memory allocation, leading to denial of service. The vulnerability is fixed in the stated versions.
Potential Impact
The vulnerability can cause denial of service by triggering out-of-bounds memory reads and invalid allocations when processing malicious PSD files with specific options enabled. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
This issue is fixed in OpenImageIO versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1. Users should upgrade to these or later versions to remediate the vulnerability. No additional mitigations are specified.
CVE-2026-63635: CWE-125: Out-of-bounds Read in AcademySoftwareFoundation OpenImageIO
Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
CVSS v3.1
Score 5.5medium
Affected software
AcademySoftwareFoundation
OpenImageIO
pkg:github/academysoftwarefoundation/OpenImageIORun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenImageIO versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1 contain an out-of-bounds read vulnerability (CWE-125) in the PSD input handling code. When a specially crafted PSD file with an invalid color_mode is processed with oiio:rawcolor or psd:rawdata enabled, the PSDInput::setup() function uses the attacker-controlled color_mode value to index fixed color-mode tables improperly. This results in a global out-of-bounds read and potentially bogus memory allocation, leading to denial of service. The vulnerability is fixed in the stated versions.
Potential Impact
The vulnerability can cause denial of service by triggering out-of-bounds memory reads and invalid allocations when processing malicious PSD files with specific options enabled. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
This issue is fixed in OpenImageIO versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1. Users should upgrade to these or later versions to remediate the vulnerability. No additional mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-17T14:11:15.482Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aad5cfd55bf5e2cf53217fe
Added to database: 09/18/2026, 15:47:09 UTC
Last enriched: 09/18/2026, 16:01:47 UTC
Last updated: 09/18/2026, 23:55:50 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.