๐Ÿ” CVE Alert

CVE-2026-7582

MEDIUM 5.3

AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in AcademySoftwareFoundation OpenImageIO up to 3.2.0.1-dev. This vulnerability affects unknown code of the file src/dds.imageio/ddsinput.cpp of the component DDS Image Handler. The manipulation results in out-of-bounds write. The attack needs to be approached locally. The exploit is now public and may be used. The patch is identified as 94ec2deec3e3bf2f2e2ff84d008e27425d626fe2. Applying a patch is advised to resolve this issue.

CWE CWE-787 CWE-119
Vendor academysoftwarefoundation
Product openimageio
Published May 1, 2026
Stay Ahead of the Next One

Get instant alerts for academysoftwarefoundation openimageio

Be the first to know when new medium vulnerabilities affecting academysoftwarefoundation openimageio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

AcademySoftwareFoundation / OpenImageIO
3.2.0.1-dev

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360529 vuldb.com: https://vuldb.com/vuln/360529/cti vuldb.com: https://vuldb.com/submit/803548 github.com: https://github.com/biniamf/pocs/tree/main/oiio_ddsinput-readimg github.com: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5131 github.com: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2 github.com: https://github.com/AcademySoftwareFoundation/OpenImageIO/

Credits

๐Ÿ” biniam (VulDB User)