CVE-2020-13493: Pixar Openusd

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

Affected products

  • Pixar Openusd: version 20.05 only

Published 2020-12-02. Last modified 2026-06-17.