CVE-2026-45696 | AcademySoftwareFoundation OpenEXR up to 3.4.10 Exrcheck Utility ht_undo_impl i32[] heap-based overflow (GHSA-gjpj-qv64-vwhf / Nessus ID 321448)
A vulnerability identified as critical has been detected in AcademySoftwareFoundation OpenEXR up to 3.4.10. Affected is the function ht_undo_impl of the component Exrcheck Utility. This manipulation of the argument i32[] causes heap-based buffer overflow.
This vulnerability appears as CVE-2026-45696. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.