SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-68514

MEDIUM · CVSS 5.5 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The PyOpenEXR Python bindings in OpenEXR versions 3.3.0 to 3.3.12 and 3.4.0 to 3.4.13 are vulnerable to a heap buffer overflow when processing specially crafted deep scanline EXR files, which can lead to memory corruption and application crashes. This vulnerability primarily affects developers and organizations in the motion picture industry that utilize OpenEXR for image processing, and they should prioritize upgrading to versions 3.3.13 or 3.4.14 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-68514
Severity
MEDIUM
CVSS
5.5
EPSS
0.19%

Original NVD Description

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap out-of-bounds write triggered when reading a crafted deep scanline EXR file. When a deep file declares a literal channel named left alongside layer-prefixed RGB channels left.R, left.G, and left.B, the wrapper processes the literal left channel first and allocates a scalar deep sample array for it, then reuses that same array as the coalesced destination for the prefixed RGB group. The deep reader registers sample slices with an RGB stride (three lanes) into storage that was allocated with scalar shape, so decoding the deep samples writes past the allocation. Opening such a file through the default public Python API, OpenEXR.File(path), causes a heap buffer overflow during normal deep sample decode, leading to memory corruption and a crash. This issue is fixed in versions 3.3.13 and 3.4.14.