CVE-2026-39886 - Vulnerability Analysis
MediumCVSS: 5.3Last Updated: April 22, 2026
OpenEXR - Integer Overflow
Published: April 21, 2026Updated: April 22, 2026PoC AvailableRemote Exploitable
Overview
OpenEXR 3.4.0 through 3.4.9 contains a signed integer overflow caused by unchecked accumulation of bytes-per-line in HTJ2K decompression, letting attackers cause heap out-of-bounds write via crafted EXR files, exploit requires crafted file with specific channel and width values.
Severity & Score
Severity: Medium
CVSS Score: 5.3
Impact
Attackers can cause heap out-of-bounds write, potentially leading to memory corruption or code execution.
Mitigation
Update to version 3.4.10 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-39886
- Severity
- Medium
- CVSS Score
- 5.3
- Type
- integer_overflow
- Status
- confirmed
CWE
- CWE-190
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L