CVE-2026-68516: CWE-787: Out-of-bounds Write in AcademySoftwareFoundation openexr
OpenEXR versions 3.4.0 through 3.4.13 contain an out-of-bounds write vulnerability in the HTJ2K decoder path. A crafted HTJ2K-compressed EXR file with specific JPEG 2000 SIZ fields can cause a stack out-of-bounds write, leading to a denial of service by crashing the application. This occurs because the decoder does not properly reject image-offset/tile-grid geometry where the first tile is outside the visible image. The issue is fixed in version 3.4.14.
AI Analysis
Technical Summary
The vulnerability in OpenEXR (CVE-2026-68516) affects versions 3.4.0 through 3.4.13 and involves an out-of-bounds write in the vendored OpenJPH AVX2 decoder used for HTJ2K-compressed EXR images. Specifically, when a crafted EXR file has JPEG 2000 SIZ fields that place the first tile outside the visible image, the decoder processes invalid tile and codeblock geometry, causing a stack out-of-bounds write. Although OpenEXR validates the decoded codestream dimensions against the EXR chunk size, it fails to reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This results in a denial of service via application crash. The vulnerability is addressed in OpenEXR version 3.4.14.
Potential Impact
This vulnerability can cause a denial of service by crashing applications that decode maliciously crafted HTJ2K-compressed EXR images. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade OpenEXR to version 3.4.14 or later, where this vulnerability is fixed. No other mitigation or workaround is indicated.
CVE-2026-68516: CWE-787: Out-of-bounds Write in AcademySoftwareFoundation openexr
Description
OpenEXR versions 3.4.0 through 3.4.13 contain an out-of-bounds write vulnerability in the HTJ2K decoder path. A crafted HTJ2K-compressed EXR file with specific JPEG 2000 SIZ fields can cause a stack out-of-bounds write, leading to a denial of service by crashing the application. This occurs because the decoder does not properly reject image-offset/tile-grid geometry where the first tile is outside the visible image. The issue is fixed in version 3.4.14.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/academysoftwarefoundation/openexrRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in OpenEXR (CVE-2026-68516) affects versions 3.4.0 through 3.4.13 and involves an out-of-bounds write in the vendored OpenJPH AVX2 decoder used for HTJ2K-compressed EXR images. Specifically, when a crafted EXR file has JPEG 2000 SIZ fields that place the first tile outside the visible image, the decoder processes invalid tile and codeblock geometry, causing a stack out-of-bounds write. Although OpenEXR validates the decoded codestream dimensions against the EXR chunk size, it fails to reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This results in a denial of service via application crash. The vulnerability is addressed in OpenEXR version 3.4.14.
Potential Impact
This vulnerability can cause a denial of service by crashing applications that decode maliciously crafted HTJ2K-compressed EXR images. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade OpenEXR to version 3.4.14 or later, where this vulnerability is fixed. No other mitigation or workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-30T16:19:08.082Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8cc43dacd9273b4935896b
Added to database: 08/24/2026, 22:22:53 UTC
Last enriched: 08/24/2026, 23:07:05 UTC
Last updated: 08/24/2026, 23:38:32 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.