Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-34545

OpenEXR: OpenEXR: Remote code execution via crafted EXR files (important)
Back to all
CVE

CVE-2026-34545

OpenEXR: OpenEXR: Remote code execution via crafted EXR files (important)

DOCUMENTATION: A flaw was found in OpenEXR, an image storage format for the motion picture industry. An attacker can exploit this vulnerability by providing a specially crafted .exr file with HTJ2K compression and a specific channel width. This allows controlled data to be written beyond the output heap buffer, leading to a heap write overflow. This issue can ultimately result in remote code execution on systems that decode these malicious EXR images. 

            STATEMENT: This is an Important vulnerability in OpenEXR that could lead to remote code execution. The flaw occurs when processing a specially crafted EXR image file with HTJ2K compression and a specific channel width, resulting in a heap write overflow. Red Hat products that utilize OpenEXR for image decoding are affected if they process untrusted EXR files.

            MITIGATION: Restrict the processing of untrusted OpenEXR image files. Systems should be configured to only decode .exr files from known and trusted sources to prevent exploitation of the heap write overflow vulnerability. This operational control limits exposure to malicious input.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.4
-
4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
-
C
H
U
-

Related Resources

No items found.

References

https://access.redhat.com/security/cve/CVE-2026-34545

Severity

0

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
0
EPSS Probability
0.00034%
EPSS Percentile
0.10362%
Introduced Version
0
Fix Available
3.4.9-r0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading