PatchSiren

AcademySoftwareFoundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AcademySoftwareFoundation CVE published 2026-06-18

CVE-2026-45696

CVE-2026-45696 is a high-severity vulnerability in OpenEXR, a widely-used image format in the motion picture industry. A heap-buffer-overflow READ vulnerability exists in the HTJ2K decoder, ht_undo_impl() in OpenEXRCore, affecting versions 3.4.0 through 3.4.11. The vulnerability occurs when the ht_undo_impl function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared wi [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-06-18

CVE-2026-44663

CVE-2026-44663 is a heap-buffer overflow vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability exists in the ht_undo_impl() function in src/lib/OpenEXRCore/internal_ht.cpp, where an integer overflow occurs when decoding a crafted HTJ2K-compressed EXR file. This leads to a corrupted offset used for pointer arithmetic, causing a heap out-of-bounds write. The [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-05-07

CVE-2026-42216

CVE-2026-42216 is a high-severity vulnerability in OpenEXR, an image storage format for the motion picture industry. The vulnerability affects versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The issue arises from the IDManifest::init() function, which reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-05-07

CVE-2026-41142

CVE-2026-41142 is an integer overflow vulnerability in the OpenEXR image storage format, specifically in the ImageChannel::resize function. This issue affects OpenEXR versions from 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The vulnerability leads to a heap out-of-bounds write via the OpenEXRUtil public API, posing a significant risk to applications utilizing OpenEXR. The C [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-04-21

CVE-2026-40244

CVE-2026-40244 is a high-severity vulnerability in OpenEXR, an image storage format used in the motion picture industry. The vulnerability affects OpenEXR versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7. The issue is caused by an integer overflow in the `internal_dwa_compressor.h` file, which can lead to potential code execution. The vulnerability has a CVSS score of 8.4 and is [truncated]