CVE-2026-42217Disclosure(openexr / openexr)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openexr

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
openexr

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-13: 4Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 305-0705-0805-13
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure2
2026-05-081
General1
2026-05-134
Disclosure2General2
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42217 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry lists a critical CVE-2026-42217 with a high CVSS score, but provides no further details on exploitation or mitigation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42217 (CVSS 9.8) — openexr openexr. CVE: CVE-2026-42217 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    Critical CVE‑2026‑42217 with a high CVSS score is disclosed, but no PoC, exploit, or remediation details are provided.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42217 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture…

    Post summary

    The text announces a critical CVE (CVE-2026-42217) for OpenEXR with detailed CVSS scoring, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    1000041
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42217-openexr-openexr #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet only references a URL and hashtags, offering no substantive details about CVE‑2026‑42217.

    0000024
    210 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-42217 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42217 #CVE-2026-42217 #CVE #Medium #CyberSecurity #InfoSec https://t.co/onxJsDafdr

    Post summary

    The tweet simply announces CVE‑2026‑42217 with a medium severity rating and links to the NVD entry, without providing technical detail, PoC, or exploitation context.

    0000057
    155 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42217 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 t… https://www.cve.org/CVERecord?id=CVE-2026-42217

    Post summary

    The post announces the CVE‑2026‑42217 vulnerability related to OpenEXR’s EXR format specification, but provides no technical details, exploits, or mitigation guidance.

    0000092
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42217 Integer Overflow in OpenEXR Variable-Length Integer Decoding Versions 3.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42217 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-42217, an integer overflow in OpenEXR's variable‑length integer decoding, and provides links to notification and details without indicating exploitation, patches, or a PoC.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenexropenexr---

Explore more