Back to VulnFeed / CVE-2026-42216
root@hackertop:~/vulnfeed/CVE-2026-42216#
CVE-2026-42216 MEDIUM Memory Corruption ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10 EXR File IDManifest::init out-of-bounds

OpenEXR 14d ago Impact pending confirmation
LIFECYCLE
6.0 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability, which was classified as critical, was found in AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10. This affects the function IDManifest::init of the component EXR File Handler. Upgrading to version 3.2.9, 3.3.11 or 3.4.11 eliminates this vulnerability.
Root Cause Analysis
CWE is classifying the issue as CWE-125. The product reads data past the end, or before the beginning, of the intended buffer.

Impact: This is going to have an impact on confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 3.2.9, 3.3.11 or 3.4.11 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-42216 · CVSS 6.0 · Active Threat