CVE-2026-45696: OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)

Published Jun 18, 2026
·
Updated

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, htundoimpl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The htundoimp function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared width as the iteration count. The codestream embedded in the EXR chunk can declare different (smaller) tile/line dimensions than the EXR header advertises, but htundoimpl() does not validate this — it pulls width 32-bit samples from curline->i32[] without checking the OpenJPH line buffer's actual length. A crafted EXR file produces a 4-byte heap-buffer-overflow READ immediately after a buffer allocated by ojph::local::codestream::finalizealloc(). The bug is reachable through the standard scanline-decode entry point used by every consumer of exrdecodingrun/Imf::checkOpenEXRFile, including thumbnailers, asset pipelines, and the exrcheck utility — i.e. any application that opens untrusted EXR files. The result is a deterministic crash (DoS) and potential adjacent-heap leak. This issue has been fixed in version 3.4.12.

Affected Software

2 affected components
OpenEXR OpenEXR>=3.4.0<=3.4.11
OpenEXR OpenEXR>=3.4.0<3.4.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenEXR to a version that resolves this vulnerability.

    Fixed in 3.4.12

Event History

Jun 18, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45696?

CVE-2026-45696 has a high severity rating of 8.3 according to the CVSS score.

2

What type of vulnerability is associated with CVE-2026-45696?

CVE-2026-45696 is a vulnerability that involves a heap buffer over-read in the HTJ2K decoder.

3

Which versions of OpenEXR are affected by CVE-2026-45696?

CVE-2026-45696 affects versions of OpenEXR from 3.4.0 through 3.4.11.

4

How do I fix CVE-2026-45696?

To fix CVE-2026-45696, upgrade to OpenEXR version 3.4.12 or later.

5

What impact does CVE-2026-45696 have on systems using OpenEXR?

CVE-2026-45696 can lead to denial of service (DoS) due to the heap buffer over-read.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203