OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked value as the loop bound while filling the fixed strings[8] array, writing pointers beyond the stack buffer and into adjacent state, resulting in memory corruption and denial of service. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), numberOfElements, and strings[8], which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-121",
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59181.json"
}{
"cpe": [
"cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*",
"cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*",
"cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.0.20.0"
},
{
"introduced": "3.1.0.0"
},
{
"last_affected": "3.1.15.0"
},
{
"introduced": "3.2.0.0-dev"
},
{
"last_affected": "3.2.0.0-dev"
},
{
"introduced": "3.2.0.2-dev"
},
{
"last_affected": "3.2.0.2-dev"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59181.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "53232011962332084265322161100540499472",
"length": 129
},
"id": "CVE-2026-59181-98715f9a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openimageio/commit/908f22f5528e88e5e96184c194caa26b54b2b85f",
"target": {
"file": "src/cineon.imageio/cineoninput.cpp",
"function": "init"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"304537867104194686217847159422051901506",
"76046937590772677535813914712009910215",
"83574833487603711825349931918493220160",
"329739121090699783608150256815831211751",
"307744904009172170690683500841611408873",
"280810304863004900503885225314759178585",
"282707422132669296828596866273687978630",
"71514690323833166023566832704909468826",
"111060983553290891640739032828310732948",
"144260387314529572433422282524130597915",
"276697353794009308522546105157293774120",
"163666572319659912056380866153033532433",
"53273892900364246560861745049694098585",
"191989878551613106893052278662851938253",
"162925776775293211043036373107466019025",
"250679938782683902396302828085806647632",
"185615443219239648244066207599365729845",
"322462235960719071018572444729267911",
"85193068514011089214772017145305328841",
"320297287774461239377067455551854977758",
"224501955452435510645756163979306191370"
],
"threshold": 0.9
},
"id": "CVE-2026-59181-dee29cda",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openimageio/commit/908f22f5528e88e5e96184c194caa26b54b2b85f",
"target": {
"file": "src/cineon.imageio/cineoninput.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "131738404394370470389468051923184699140",
"length": 7623
},
"id": "CVE-2026-59181-e9a51e08",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openimageio/commit/908f22f5528e88e5e96184c194caa26b54b2b85f",
"target": {
"file": "src/cineon.imageio/cineoninput.cpp",
"function": "CineonInput::open"
}
}
]
"2026-10-01T08:09:02Z"