CVE-2026-42216General(openexr / openexr)

LOWCVSS 9.1 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-130

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openexr

Threat summary

  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-13)
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
openexr

Deep dive

Activity timeline8 mentions / 2d
01345Mentions · 2026-05-07: 3Mentions · 2026-05-13: 5Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 405-0705-13
Signal classification2 categories
General
562.5%
Disclosure
337.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure1General2
2026-05-135
Disclosure2General3
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42216 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-42216 as a critical vulnerability with a CVSS 9.1 score but offers no proof‑of‑concept, exploit details, or patch information.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42216 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The provided text lists CVE-2026-42216 with a high CVSS score and critical severity, but offers no further detail such as PoC, exploit, or patch information.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42216 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture…

    Post summary

    The text announces a CVE-2026-42216 as a critical vulnerability in OpenEXR’s EXR file format, providing CVSS and severity details, but does not mention a PoC, exploit, active attacks, patch, or debunking.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42216 (CVSS 9.1) — openexr openexr. CVE: CVE-2026-42216 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The notice announces CVE-2026-42216 as a critical vulnerability with a CVSS score of 9.1, but provides no further technical details, exploit code, or mitigation guidance.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42216-openexr-openexr #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text contains only a URL and generic hashtags, offering no concrete evidence of a PoC, exploit, active use, patch, or detailed technical data about CVE-2026-42216.

    0000023
    210 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-42216 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42216 #CVE-2026-42216 #CVE #High #CyberSecurity #InfoSec https://t.co/75wsmE7ZcT

    Post summary

    The tweet merely announces a newly identified CVE with a high severity rating and links to the NVD entry, without providing technical specifics, exploitation details, or remediation guidance.

    0000056
    155 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42216 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 t… https://www.cve.org/CVERecord?id=CVE-2026-42216

    Post summary

    The note simply references CVE-2026-42216 in OpenEXR without providing further details or actionable information.

    0000093
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42216 Buffer Over-Read in OpenEXR IDManifest String Reconstruction Versions 3.0.0-3.4.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42216

    Post summary

    CVE-2026-42216 is a buffer over‑read vulnerability in OpenEXR’s IDManifest string reconstruction affecting versions 3.0.0‑3.4.10, with no PoC, exploit, patch, or active exploitation information provided.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenexropenexr---

Explore more