CVE-2026-41142
High
Published: 07 May 2026
Published
07 May 2026
Modified
07 May 2026
KEV Added
—
Patch
—
CVSS Score
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.0004
11.0th percentile
Risk Priority
18
60% EPSS · 20% KEV · 20% CVSS
Description
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer…
more
overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
Security SummaryAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)