Integer overflow in Openimageio - CVE-2026-43909
Published: May 5, 2026
Openimageio
AcademySoftwareFoundation
Description
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to integer overflow in SwapRGBABytes() in the DPX ABGR decoder when parsing a crafted kABGR DPX image with large dimensions. A remote attacker can supply a specially crafted DPX file to execute arbitrary code or cause a denial of service.
User interaction is required to open or process the crafted DPX file.