Out-of-bounds read in Openimageio - #VU129717
Published: May 5, 2026
Openimageio
AcademySoftwareFoundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in TGAInput::decode_pixel in the TGA paletted image decoder when parsing a crafted TYPE_PALETTED TGA file with 32-bit palette entries. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
User interaction is required to open a crafted file.