CVE-2026-7582: Academysoftwarefoundation Openimageio
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was detected in AcademySoftwareFoundation OpenImageIO up to 3.2.0.1-dev. This vulnerability affects unknown code of the file src/dds.imageio/ddsinput.cpp of the component DDS Image Handler. The manipulation results in out-of-bounds write. The attack needs to be approached locally. The exploit is now public and may be used. The patch is identified as 94ec2deec3e3bf2f2e2ff84d008e27425d626fe2. Applying a patch is advised to resolve this issue.
Affected products
- Academysoftwarefoundation Openimageio: version 3.2.0.1-dev only
Published 2026-05-01. Last modified 2026-06-17.