CVE Tools

Openimageio

32 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.

Openimageio CVEs per month

Dec 2022 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Openimageio CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-12240
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-0580

Products

The products that kept showing up in Openimageio's monthly top three, with their CVEs summed over those months.

  1. Openimageio322 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Openimageio.

  1. CVE-2026-43903OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release builds7.8
  2. CVE-2026-43904OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image width7.8
  3. CVE-2026-43905OpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocation7.8
  4. CVE-2026-43996OpenImageIO: Integer wraparound in bounds check of decode_pixel leads to out-of-bounds read in TGA paletted image decoder5.5
  5. CVE-2026-43907OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR)8.3
  6. CVE-2026-43908OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoder8.8
  7. CVE-2026-43909OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoder8.8
  8. CVE-2026-43906OpenImageIO: HEIF Heap overflow7.8
  9. CVE-2024-55194OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.9.8
  10. CVE-2024-55192OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).9.8
  11. CVE-2024-55193OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.9.8
  12. CVE-2023-3430Openimageio: heap-buffer-overflow in file src/gif.imageio/gifinput.cpp7.5
  13. CVE-2023-42299Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.9.8
  14. CVE-2023-42295An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c8.8
  15. CVE-2023-36183Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.7.8

The record

Peak rank
#32 in Dec 2022
Busiest month shown
Dec 2022, 24 CVEs
Months with a KEV entry
0 since Dec 2022
Monthly snapshots
2 since 2022
Openimageio's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store