OpenEXR patched two high-severity memory corruption vulnerabilities that can be triggered by decoding crafted .exr image files. CVE-2026-34545 affects OpenEXR 3.4.0 through before 3.4.7 and stems from an integer overflow in the HTJ2K decoder when processing an image with a channel width of 32768, leading to a heap-based buffer overflow with controlled out-of-bounds writes. The flaw could enable remote code execution in applications that open malicious EXR images, particularly where untrusted files are automatically parsed.
A second flaw, CVE-2026-34544, affects OpenEXR 3.4.0 through before 3.4.8 and allows an out-of-bounds write in uncompress_b44_impl() during exr_decoding_run() when handling crafted B44 or B44A-compressed EXR files. Depending on heap layout, the issue can cause immediate crashes or corrupt adjacent allocations, with the CVE classified under CWE-787 and CWE-190. Organizations using OpenEXR in media pipelines, rendering tools, or image-processing applications should upgrade to OpenEXR 3.4.8 to address both issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
OpenEXR version 3.4.8 fixed CVE-2026-34543, an information disclosure flaw in PXR24 decompression caused by an unchecked decompressed size in undo_pxr24_impl(). A crafted EXR file could leak sensitive heap memory contents through decoded pixel data when processed.
OpenEXR released version 3.4.8 to address an integer overflow that can cause an out-of-bounds write in uncompress_b44_impl() during exr_decoding_run(). Successful exploitation could cause crashes or corrupt adjacent heap allocations when decoding malicious B44 or B44A EXR images.
The CVE record for CVE-2026-34544, an integer overflow leading to out-of-bounds write in OpenEXR's uncompress_b44_impl(), was received by security-advisories@github.com. The flaw affects OpenEXR versions 3.4.0 through before 3.4.8 and can be triggered by crafted B44 or B44A EXR files.
OpenEXR released version 3.4.7 to fix an integer-overflow-driven heap-based buffer overflow in the HTJ2K decoder affecting versions 3.4.0 through before 3.4.7. A crafted EXR file using HTJ2K compression and a channel width of 32768 could trigger out-of-bounds writes and potentially remote code execution during decoding.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.