CVE-2026-41142 | AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10 EXR File ImageChannel::resize integer overflow (GHSA-m25w-72cj-q6mg / EUVD-2026-28251)
A vulnerability classified as critical has been found in AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10. Impacted is the function ImageChannel::resize of the component EXR File Handler. Performing a manipulation results in integer overflow.
This vulnerability was named CVE-2026-41142. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.