Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openimageio

First CVE: Dec 22, 2022Active for: 4 yearsTotal CVEs: 42
48.2
VTI Score
High

OpenImageIO is an image input/output library widely embedded in visual effects, animation, and 3D graphics applications, where a single vulnerability in the library can propagate across numerous downstream products and workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and parsing demands of a C++ image codec implementation that processes untrusted image files from diverse sources. The exposure recurs through weakness classes including out-of-bounds writes, heap-based buffer overflows, out-of-bounds reads, NULL-pointer dereferences, and integer overflow conditions, all typical of format parsers handling malformed or adversarial input. Defenders should prioritize inventory of downstream applications and plugins that bundle this library and treat updates as supply-chain patches rather than point fixes; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
10.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openimageio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2022
3 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-43908HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in
May 14, 20268.833NONO
CVE-2026-43909HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in
May 14, 20268.832NONO
CVE-2026-43907HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer o
May 14, 20268.331NONO
CVE-2022-41838CRITICAL
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer over
Dec 22, 20229.831NONO
CVE-2022-41837CRITICAL
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can
Dec 22, 20229.831NONO
CVE-2022-41639CRITICAL
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can
Dec 22, 20229.831NONO
CVE-2022-38143CRITICAL
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds
Dec 22, 20229.831NONO
CVE-2026-43903HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,2
May 14, 20267.830NONO
CVE-2026-43904HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp
May 14, 20267.830NONO
CVE-2026-43906HIGH
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffe
May 14, 20267.830NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
21%
52%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (19.0%)
Network34 (81.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (69.0%)
High13 (31.0%)
Unknown0 (0.0%)
User Interaction
None30 (71.4%)
Unknown0 (0.0%)
Required12 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None42 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openimageio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openimageio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openimageio's Products

View all 4 CNAs →

Top CWEs