Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-dd0b-5db3-5ace
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-dd0b-5db3-5ace.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-dd0b-5db3-5ace
Upstream
CVE-2026-34543
Withdrawn
2026-06-01T13:30:03Z
Published
2026-06-01T07:39:17Z
Modified
2026-09-15T03:33:45Z
Summary
Information disclosure via decoded pixel data from heap memory. Vulnerability introduced in 3.4.0; the affected code path does not exist in 3.1.x.
Details
References
https://advisory.echohq.com/cve/CVE-2026-34543
Affected packages
Echo
/
openexr
Package
Name
openexr
Purl
pkg:deb/echo/openexr
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.1.13-2
Database specific
source
"https://advisory.echohq.com/osv/ECHO-dd0b-5db3-5ace.json"
ECHO-dd0b-5db3-5ace - OSV