Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34589

23
FAUCET Score

CVE-2026-34589 is a buffer overflow vulnerability affecting OpenEXR versions 3.2.0 through 3.2.6, 3.3.0 through 3.3.8, and 3.4.0 through 3.4.8. The DWA lossy decoder incorrectly uses signed 32-bit arithmetic when constructing temporary block pointers, causing integer overflow on large image widths. This results in out-of-bounds memory writes to the rowBlock backing store. The vulnerability has been patched in versions 3.2.7, 3.3.9, and 3.4.9. The vulnerability carries a CVSS 3.1 score of 5.0 (Medium severity) and requires local access with low attack complexity and user interaction. An attacker must be able to supply a specially crafted EXR file to a local user. While the vulnerability does not compromise confidentiality or integrity, it can cause high-impact denial of service by corrupting memory and crashing the application. There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has received minimal community attention, with an extremely low EPSS score of 0.000090. Organizations should prioritize patching based on their use of OpenEXR in production environments, but this is not an urgent threat requiring immediate remediation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.2.0, < 3.2.7CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.9CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.9CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 72nd percentile among its peer group of 382 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.2.7
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.3.9
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.4.9
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-p8xc-w3q4-h64xhigh

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

Apr 8, 2026

References

access.redhat.com / security/cve/CVE-2026-34589
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-34589.json
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.2.7
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.3.9
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.4.9
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/security/advisories/GHSA-p8xc-w3q4-h64x
ExploitVendor Advisory