Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-59183: CWE-190: Integer Overflow or Wraparound in AcademySoftwareFoundation openexrCVE-2026-59183
0

CVE-2026-59183 is an integer overflow vulnerability in the AcademySoftwareFoundation openexr library affecting versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. The flaw occurs in the unpack_sample_table() function during decoding of crafted deep tiled EXR files, leading to a crash due to a read from an unmapped memory address. This issue impacts any application decoding deep tiled EXR files. Fixed versions include 3.2.11, 3.3.13, and 3.4.14.

Join the discussion
CVE-2026-55373: CWE-190: Integer Overflow or Wraparound in AcademySoftwareFoundation openexrCVE-2026-55373
0

OpenEXR versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an integer overflow vulnerability in the SampleCountChannel component. This flaw causes an infinite loop due to a 32-bit unsigned integer wraparound in the roundListSizeUp() helper function when processing the maximum unsigned integer value. The issue can be triggered via public APIs by setting a pixel sample count to UINT_MAX or editing the sample-count buffer. The vulnerability has been fixed in versions 3.2.10, 3.3.12, and 3.4.13.

Join the discussion
CVE-2026-55371: CWE-20: Improper Input Validation in AcademySoftwareFoundation openexrCVE-2026-55371
0

OpenEXR versions 3.4.0 through 3.4.12 contain a vulnerability due to improper input validation in the exr_attr_set_bytes() function. This flaw allows a NULL pointer dereference when a positive hint_length is provided with a NULL type_hint pointer, leading to a denial of service via a deterministic crash. The issue is fixed in version 3.4.13.

Join the discussion
CVE-2026-55059: CWE-787: Out-of-bounds Write in AcademySoftwareFoundation openexrCVE-2026-55059
0

OpenEXR versions prior to 3.2.10, 3.3.12, and 3.4.13 contain a heap out-of-bounds write vulnerability in the SampleCountChannel::set function. This occurs because the Y coordinate is incorrectly computed using dataWindow.min.x instead of dataWindow.min.y, leading to potential heap corruption and process crashes when handling deep image data windows where min.x differs from min.y. The issue is reachable via the public DeepImage API and has been fixed in the specified versions.

Join the discussion
CVE-2026-54920: CWE-190: Integer Overflow or Wraparound in AcademySoftwareFoundation openexrCVE-2026-54920
0

A vulnerability in OpenEXR versions 3.4.0 through 3.4.12 allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort when exr_start_read() is called on untrusted input. This results in a denial of service due to an assertion failure triggered by a specific QCD marker value. The issue arises from the OpenJPH library's use of an assertion that calls abort() directly, bypassing error handling. The vulnerability is fixed in version 3.4.13.

Join the discussion
CVE-2026-53532: CWE-617: Reachable Assertion in AcademySoftwareFoundation openexrCVE-2026-53532
0

A reachable assertion vulnerability exists in AcademySoftwareFoundation's OpenEXR versions 3.4.0 through 3.4.12. A crafted HTJ2K-compressed EXR file with a specific QCD marker causes an unconditional process abort when processed by exr_start_read(), leading to denial of service. The issue stems from the OpenJPH library using an assertion instead of recoverable error handling for invalid quantization delta parameters. This vulnerability is fixed in version 3.4.13.

Join the discussion
CVE-2026-68516: CWE-787: Out-of-bounds Write in AcademySoftwareFoundation openexrCVE-2026-68516
0

OpenEXR versions 3.4.0 through 3.4.13 contain an out-of-bounds write vulnerability in the HTJ2K decoder path. A crafted HTJ2K-compressed EXR file with specific JPEG 2000 SIZ fields can cause a stack out-of-bounds write, leading to a denial of service by crashing the application. This occurs because the decoder does not properly reject image-offset/tile-grid geometry where the first tile is outside the visible image. The issue is fixed in version 3.4.14.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/academysoftwarefoundation/openexr
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses