Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-bef0-7838-a483
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-bef0-7838-a483.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-bef0-7838-a483
Upstream
CVE-2026-40244
Withdrawn
2026-06-01T13:30:03Z
Published
2026-06-01T07:39:17Z
Modified
2026-09-15T03:33:45Z
Summary
Integer overflow in internal_dwa_compressor.h:1722. Vulnerability introduced in 3.2.0; the affected code path does not exist in 3.1.x.
Details
References
https://advisory.echohq.com/cve/CVE-2026-40244
Affected packages
Echo
/
openexr
Package
Name
openexr
Purl
pkg:deb/echo/openexr
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.1.13-2
Database specific
source
"https://advisory.echohq.com/osv/ECHO-bef0-7838-a483.json"
ECHO-bef0-7838-a483 - OSV