Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-48074


OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.


Published

2025-08-01T17:15:52.193

Last Modified

2025-08-13T19:18:13.987

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openexr openexr 3.3.2 Yes

References