OpenImageIO is an image input/output library widely embedded in visual effects, animation, and 3D graphics applications, where a single vulnerability in the library can propagate across numerous downstream products and workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and parsing demands of a C++ image codec implementation that processes untrusted image files from diverse sources. The exposure recurs through weakness classes including out-of-bounds writes, heap-based buffer overflows, out-of-bounds reads, NULL-pointer dereferences, and integer overflow conditions, all typical of format parsers handling malformed or adversarial input. Defenders should prioritize inventory of downstream applications and plugins that bundle this library and treat updates as supply-chain patches rather than point fixes; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openimageio over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43908HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in | May 14, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-43909HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in | May 14, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-43907HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer o | May 14, 2026 | 8.3 | 31 | NO | NO |
CVE-2022-41838CRITICAL A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer over | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-41837CRITICAL An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-41639CRITICAL A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38143CRITICAL A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-43903HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,2 | May 14, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-43904HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp | May 14, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-43906HIGH OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffe | May 14, 2026 | 7.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openimageio.
Media articles that mention a CVE ID that affects a product developed by Openimageio — matched by CVE ID, not by vendor name.