CVE-2017-12596: Openexr

High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.

Affected products

  • Openexr Openexr: version 2.2.0 only

Published 2017-08-07. Last modified 2026-06-17.