OpenEXR is a narrowly focused but prominently deployed image-file library that implements the Industrial Light & Magic format and is embedded across visual-effects, animation, and graphics-processing pipelines. Despite its focused product scope, the library's prevalence in professional media-production software and its role in parsing untrusted image data create a significant attack surface within that domain. Vulnerabilities affecting the library concentrate in parsing and memory-handling code and recur through weakness classes including integer overflow, out-of-bounds read and write conditions, and uncontrolled resource consumption—patterns typical of binary-format parsers handling variable-length or nested structures. The exposure reflects the low-level memory-safety demands of a C++ image codec rather than a broad security posture concern, but a flaw here can propagate to every downstream application that embeds the library. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openexr over time
Signals from CVEs in this vendor scope (78 CVEs).
78 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42216CRITICAL OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9 | May 7, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-42217CRITICAL OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9 | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-41142HIGH OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9 | May 7, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-48072CRITICAL OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a he | Jul 31, 2025 | 9.1 | 32 | NO | NO |
CVE-2026-44663HIGH OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflo | Jun 18, 2026 | 7.1 | 30 | NO | NO |
CVE-2026-34588HIGH OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, | Apr 6, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-27622HIGH OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixel | Mar 3, 2026 | 7.8 | 29 | NO | NO |
CVE-2017-9115HIGH In OpenEXR 2.2.0, an invalid write of size 2 in the = operator function in half.h could cause the application to crash or execute arbitrary code. | May 21, 2017 | 8.8 | 29 | NO | NO |
CVE-2026-45696MEDIUM OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Th | Jun 18, 2026 | 6.5 | 28 | NO | NO |
CVE-2021-23169HIGH A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permiss | Jun 8, 2021 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (78 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openexr.
Media articles that mention a CVE ID that affects a product developed by Openexr — matched by CVE ID, not by vendor name.