CVE-2026-27622 | AcademySoftwareFoundation OpenEXR up to 3.2.5/3.3.7/3.4.5 EXR File Parser readPixels out-of-bounds write (GHSA-cr4v-6jm6-4963)
A vulnerability, which was classified as critical, was found in AcademySoftwareFoundation OpenEXR up to 3.2.5/3.3.7/3.4.5. Affected is the function CompositeDeepScanLine::readPixels of the component EXR File Parser. Such manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2026-27622. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.