Sploitus

CVE-2026-43996

No indexed exploits for CVE-2026-43996 yet

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, the bounds check in TGAInput::decode_pixel computes k + palbytespp as unsigned 32-bit arithmetic. When k = 0xFFFFFFFC and palbytespp = 4, the addition wraps to 0, which compares less than palette_alloc_size and passes the check. The subsequent palette access uses the unwrapped k (0xFFFFFFFC) as the index, reading ~4 GB past the start of the palette buffer β€” SEGV. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.

Affected products
Openimageio
Openimageio
< 3.0.18.0, 3.1.13.0, 3.2.0.0, 3.2.0.2
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2026-05-14
CVE-2026-43996 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-43996 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-43996 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β€” not that no exploit exists.