CVE-2026-34588General(openexr / openexr)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openexr openexr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-190CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openexr

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openexr

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-06: 2Mentions · 2026-05-03: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-05-03: 104-0605-03
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-062
General2
2026-05-031
Patch1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-34588: signed 32-bit overflow in OpenEXR PIZ wavelet decompress. Crafted EXR file = remote code execution. No auth needed. Patch now. #CVE #infosecurity #devsecops #devops #developers #python info: https://www.valtersit.com/cve/2026/04/cve-2026-34588/

    Post summary

    The vulnerability CVE‑2026‑34588 is a signed 32‑bit overflow in OpenEXR PIZ wavelet decompression that allows unauthenticated remote code execution; a patch is now available.

    0000087
    889 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before … https://www.cve.org/CVERecord?id=CVE-2026-34588 ----- Traducción: CVE-2026-34588 Ope… http://infoflow.cloud`

    Post summary

    The post merely references CVE‑2026‑34588 for OpenEXR without providing any technical, exploit, or mitigation details.

    0000029
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before … https://www.cve.org/CVERecord?id=CVE-2026-34588

    Post summary

    The post merely cites CVE-2026-34588 with a link to its record and provides no further technical or exploitation details.

    00000201
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenexropenexr---

Explore more