CVE-2026-34380 | AcademySoftwareFoundation OpenEXR up to 3.2.6/3.3.8/3.4.8 EXR File Parser internal_pxr24.c undo_pxr24_impl integer overflow (GHSA-q3v8-hw4m-59w5)
A vulnerability was found in AcademySoftwareFoundation OpenEXR up to 3.2.6/3.3.8/3.4.8. It has been rated as problematic. Affected by this issue is the function undo_pxr24_impl in the library src/lib/OpenEXRCore/internal_pxr24.c of the component EXR File Parser. The manipulation leads to integer overflow.
This vulnerability is referenced as CVE-2026-34380. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.