#VU125328 Heap-based buffer overflow in OpenEXR - CVE-2026-34545
Published: April 8, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the HTJ2K decoder in internal_ht.cpp when parsing a crafted EXR file with HTJ2K compression. A remote attacker can supply a specially crafted EXR file to execute arbitrary code.
User interaction is required to open or otherwise process the crafted file.