Vulnerabilities & PatchesEmerging1 src
CVE-2026-68513 - OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision
CVE ID : CVE-2026-68513
Published : Aug. 25, 2026, 8:17 p. m.
• 55 minutes ago
Description : OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3. 3. 0 through 3. 3. 12 and 3. 4. 0 through 3. 4. 13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels.
When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left. R, left. G, and left.
B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR. File(path) decodes the pixels.