CVE-2026-50291

Source
https://cve.org/CVERecord?id=CVE-2026-50291
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50291.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50291
Aliases
  • GHSA-q3c7-3225-66h7
Downstream
Published
2026-09-17T21:33:44Z
Modified
2026-09-19T08:08:49Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.cpp:399)
Details

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application linked to OpenImageIO can reach BMP palette handling in src/bmp.imageio/bmpinput.cpp with an empty color table. BmpInput::read_native_scanline then performs an invalid palette read while decoding an RLE-compressed scanline, causing a process crash and denial of service. This issue is fixed in versions 3.0.16.0 and 3.1.11.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-125"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50291.json"
}
References

Affected packages

Git / github.com/academysoftwarefoundation/openimageio

Affected ranges

Type
GIT
Repo
https://github.com/academysoftwarefoundation/openimageio
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.0.16.0"
        },
        {
            "introduced":  "3.1.0.0"
        },
        {
            "fixed":  "3.1.11.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Arnold-3.*
Arnold-3.4.72.0
Release-0.*
Release-0.10.0
Release-1.*
Release-1.0.0
Release-1.0.1
Release-1.1.0
Release-1.1.0-beta1
Release-1.1.0-beta2
Release-1.1.0-beta3
Release-1.1.0-beta4
Release-1.1.1
Release-1.3.0-dev
Release-1.3.1-dev
Release-1.3.2-dev
Release-1.3.3-dev
Release-1.3.4-dev
Release-1.3.5
Release-1.3.5-dev
Release-1.3.6-dev
Release-1.4.1dev
Release-1.4.2dev
Release-1.4.3dev
Release-1.4.4dev
Release-1.4.5dev
Release-1.4.6RC1
Release-1.5.0dev
Release-1.5.1dev
Release-1.5.2dev
Release-1.5.3dev
Release-1.5.4dev-pre-SIMD
Release-1.5.5dev
Release-1.5.6dev
Release-1.5.7dev
Release-1.6.1dev
Release-1.6.2dev
Release-1.6.3dev
Release-1.6.4dev
Release-1.6.6beta
Release-1.7.0dev
Release-1.7.1dev
Release-1.7.2dev
Release-1.7.3dev
Release-1.7.4dev
Release-1.7.5beta
Release-1.7.6RC1
Release-1.8.0dev
Release-1.8.1dev
Release-1.8.2dev
Release-1.8.3dev
Release-1.8.4dev
Release-1.9.1dev
Release-1.9.2dev
Release-1.9.3dev
Release-1.9.4dev
Release-2.*
Release-2.0.0-beta1
Release-2.0.1-RC1
Release-2.1.0-dev
Release-2.1.1-dev
Release-2.1.2-dev
Release-2.1.3-dev
Release-2.1.4.0-dev
Release-2.1.5.0-dev
Release-2.1.7-beta
Release-2.1.8.0-RC1
Release-2.2.0.0-dev
Release-2.2.1.0-dev
Release-2.2.1.1-dev
Release-2.2.2.0-dev
Release-2.2.3.0-dev
Release-2.3.0.0-dev
Release-2.3.1.0-dev
Release-2.3.2.0-dev
Release-2.3.3.0-dev
Release-2.3.4.0-dev
arnold-3.*
arnold-3.4.71.0
spi-Arn3.*
spi-Arn3.4.71.0
spi-Arn3.4.72.0
spi-Arn3.4.73.6
spi-Arn3.4.73.7
spi-Arn3.5.0.0
spi-Arn3.5.10.0
spi-Arn3.5.11.0
spi-Arn3.5.12.0
spi-Arn3.5.13.1
spi-Arn3.5.14.0
spi-Arn3.5.16.0
spi-Arn3.5.2.0
spi-Arn3.5.24.0
spi-Arn3.5.25.0
spi-Arn3.5.26.0
spi-Arn3.5.28.0
spi-Arn3.5.31.0
spi-Arn3.5.35.0
spi-Arn3.5.37.0
spi-Arn3.5.41.0
spi-Arn3.5.45.0
spi-Arn3.5.45.1
spi-Arn3.5.48.0
spi-Arn3.5.5.0
spi-Arn3.5.50.0
spi-Arn3.5.66.0
spi-Arn3.5.68.0
spi-Arn3.5.75.0
spi-Arn3.5.8.0
spi-Arn3.5.82.0
spi-Arn3.5.90.0
spi-Arn3.5.91.0
spi-Arn3.5.93.10
spi-Arn3.6.18.0
spi-Arn3.6.21.3
spi-Arn3.6.27.0
spi-Arn3.6.33.4
spi-Arn3.6.36.0
spi-Arn3.6.64.6
spi-Arn3.6.69.3
spi-Arn3.6.7.1
spi-Arn3.6.72.1
spi-Arn3.7.23.3
spi-Arn3.7.25.0
spi-Arn3.7.42.0
Other
spi-SpComp2-v20
spi-SpComp2-v9
spi-spcomp2-release-38.*
spi-spcomp2-release-38.0
spi-spcomp2-release-39.*
spi-spcomp2-release-39.1
spi-spcomp2-release-41.*
spi-spcomp2-release-41.0
spi-spcomp2-release-42.*
spi-spcomp2-release-42.0-rhel7
spi-spcomp2-release-43.*
spi-spcomp2-release-43.0
spi-spcomp2-release-44.*
spi-spcomp2-release-44.0
spi-spcomp2-release-44.1
spi-spcomp2-release-44.2
spi-spcomp2-release-45.*
spi-spcomp2-release-45.0
spi-spcomp2-release-45.1
spi-spcomp2-release-45.3
spi-spcomp2-release-45.4
spi-spcomp2-release-47.*
spi-spcomp2-release-47.0
spi-spcomp2-release-48.*
spi-spcomp2-release-48.0
spi-spcomp2-release-49.*
spi-spcomp2-release-49.1
spi-v7-Arn3.*
spi-v7-Arn3.4.73.3
spi-v8-Arn3.*
spi-v8-Arn3.4.73.6
spiArn-3.*
spiArn-3.6.74.0
spiArn-3.6.84.0
spiArn-3.6.86.0
spiArn-3.6.94.0
spiArn3.*
spiArn3.5.45.0
spiArn3.5.45.1
spiArn3.5.48.0
spiArn3.5.50.0
spiArn3.5.66.0
spiArn3.5.68.0
spiArn3.5.75.0
spiArn3.5.82.0
v2.*
v2.3.5.0-dev
v2.3.6.0-dev
v2.4.0.0-dev
v2.4.0.1-dev
v2.4.0.2-dev
v2.4.0.3-dev
v2.4.1.1-dev
v2.4.2.0-dev
v2.4.2.1-dev
v2.4.2.2-dev
v2.5.0.0-dev
v2.5.2.0-dev
v2.6.1.0-dev
v2.6.2.0-dev
v2.6.5.0-dev
v3.*
v3.0.0.0-beta1
v3.0.0.1-beta2
v3.0.0.2-RC1
v3.0.0.3
v3.0.1.0
v3.0.10.0
v3.0.10.1
v3.0.11.0
v3.0.12.0
v3.0.13.0
v3.0.14.0
v3.0.15.0
v3.0.2.0
v3.0.3.0
v3.0.3.1
v3.0.4.0
v3.0.5.0
v3.0.6.0
v3.0.6.1
v3.0.7.0
v3.0.8.0
v3.0.8.1
v3.0.9.0
v3.1.10.0
v3.1.4.0-beta
v3.1.5.0-beta2
v3.1.6.0-rc1
v3.1.6.1
v3.1.6.2
v3.1.7.0
v3.1.8.0
v3.1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50291.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "219918401886650234860481535177494602402",
            "length":  3071
        },
        "id":  "CVE-2026-50291-382eb9be",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/ee3370d004d5895554239b4302c59eedb721f086",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::read_native_scanline"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "271152986554567725245163009728115288330",
                "250610939069690244734984585110921696099",
                "174572620956024850142349245836594455771",
                "11562038605390118269496955679560589861",
                "316736059112572731918773024439197936909",
                "239087129050474577171564380257553227751",
                "32673811340366311783083454945276305963",
                "286744465660610250033678043051175761237"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-50291-55b97b1f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/ee3370d004d5895554239b4302c59eedb721f086",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "271152986554567725245163009728115288330",
                "250610939069690244734984585110921696099",
                "174572620956024850142349245836594455771",
                "11562038605390118269496955679560589861",
                "316736059112572731918773024439197936909",
                "239087129050474577171564380257553227751",
                "32673811340366311783083454945276305963",
                "286744465660610250033678043051175761237"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-50291-578f8a9a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/91500ed58ce927b7e710c6bbc3b7f795bb0791b5",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "140269761171456252019457581629894309302",
                "144795421093974837049092692731537861357",
                "10861313583890422211461092681708154969",
                "11562038605390118269496955679560589861",
                "316736059112572731918773024439197936909",
                "239087129050474577171564380257553227751",
                "32673811340366311783083454945276305963",
                "286744465660610250033678043051175761237"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-50291-6d6f22f6",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/be984856e315e0a82cd866745b544c8c4cb8bd45",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "219918401886650234860481535177494602402",
            "length":  3071
        },
        "id":  "CVE-2026-50291-8cc32f1d",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/be984856e315e0a82cd866745b544c8c4cb8bd45",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::read_native_scanline"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "130909013262619158153176773603066427547",
            "length":  3839
        },
        "id":  "CVE-2026-50291-93983c16",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/91500ed58ce927b7e710c6bbc3b7f795bb0791b5",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::open"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "125681824904607418669852347905272837880",
            "length":  3826
        },
        "id":  "CVE-2026-50291-abda778a",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/be984856e315e0a82cd866745b544c8c4cb8bd45",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::open"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "219918401886650234860481535177494602402",
            "length":  3071
        },
        "id":  "CVE-2026-50291-ad605baa",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/91500ed58ce927b7e710c6bbc3b7f795bb0791b5",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::read_native_scanline"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "130909013262619158153176773603066427547",
            "length":  3839
        },
        "id":  "CVE-2026-50291-f72240d9",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/academysoftwarefoundation/openimageio/commit/ee3370d004d5895554239b4302c59eedb721f086",
        "target":  {
            "file":  "src/bmp.imageio/bmpinput.cpp",
            "function":  "BmpInput::open"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:08:49Z"