CVE-2026-42217Openexr · Openexr
Vulnerability data via NVD (ingested)
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42217product:"Openexr Openexr"http.html:"Openexr"More intel sources (5)
vuln:CVE-2026-42217vulnerabilities.cve_id: CVE-2026-42217CVE-2026-42217CVE-2026-42217"CVE-2026-42217" exploit -site:nvd.nist.gov