CVE-2026-42216Openexr · Openexr
Vulnerability data via NVD (ingested)
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42216product:"Openexr Openexr"http.html:"Openexr"More intel sources (5)
vuln:CVE-2026-42216vulnerabilities.cve_id: CVE-2026-42216CVE-2026-42216CVE-2026-42216"CVE-2026-42216" exploit -site:nvd.nist.gov