CVE-2026-34588 | AcademySoftwareFoundation OpenEXR up to 3.1.13/3.2.6/3.3.8/3.4.8 EXR File Parser internal_exr_undo_piz out-of-bounds (GHSA-588r-cr5c-w6hf)
A vulnerability, which was classified as problematic, was found in AcademySoftwareFoundation OpenEXR up to 3.1.13/3.2.6/3.3.8/3.4.8. The impacted element is the function internal_exr_undo_piz of the component EXR File Parser. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-34588. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.