CVE-2025-15506: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-15506 is an out-of-bounds read vulnerability in AcademySoftwareFoundation OpenColorIO (OCIO) affecting versions up to and including 2.5.0. The flaw resides in the ConvertToRegularExpression function within src/OpenColorIO/FileRules.cpp, where an incorrect pointer index derived from a potentially longer transformed string (globString) is used to access the original, potentially shorter globPattern string, causing an out-of-bounds memory access. The vulnerability was reported on December 25, 2025, patched on January 11, 2026, and publicly disclosed the same day. It carries a CVSS v3.1 base score of 3.3 (Low) (GitHub Advisory, VulDB).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The bug occurs in ThrowInvalidRegex (line 55 of FileRules.cpp): when processing a glob pattern with case-insensitive matching enabled, each alphabetic character is expanded to a [xX]-style bracket expression, producing a globString that is longer than the original globPattern. The code incorrectly passed globPattern + idx (an index into the longer globString) to ThrowInvalidRegex, which then attempted to read past the end of globPattern. The fix, applied in commit ebdbb75, changes the argument to &globString[idx] so the correct string is indexed. Exploitation requires local access and the ability to supply a malformed YAML configuration file containing a FileRules section with an invalid regular expression pattern (GitHub Issue #2228, GitHub PR #2231, Patch Commit).

Impact

Successful exploitation causes a denial-of-service condition by crashing the application through an out-of-bounds memory read, confirmed via AddressSanitizer (ASAN) reporting a heap-use-after-free/out-of-bounds access in strlen. There is no impact on confidentiality or data integrity — only availability is affected (CVSS availability impact: Low). The scope is limited to the local system running OpenColorIO, with no evidence of lateral movement potential or sensitive data exposure (GitHub Issue #2228, GitHub Advisory).

Exploitability

A public proof-of-concept exploit has been disclosed and is referenced in the CVE record (hosted at https://github.com/oneafter/1225/blob/main/uaf), though no evidence of active in-the-wild exploitation has been observed. The vulnerability requires low privileges and local access, limiting its practical attack surface. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (VulDB, GitHub Advisory).

Exploitation steps

  1. Prepare a malformed YAML config: Craft an OpenColorIO YAML configuration file containing a FileRules section with a glob pattern that, when case-insensitive expansion is applied, produces a globString longer than the original globPattern and includes an unmatched [ bracket character.
  2. Trigger config parsing: As a local user with access to the system, invoke an application or tool that uses OpenColorIO (e.g., a custom harness or any OCIO-integrated DCC tool) and supply the malformed YAML config via Config::CreateFromStream() or equivalent API.
  3. Trigger out-of-bounds read: During YAML parsing, OCIOYaml::Read processes the FileRules section, calling ValidateRegularExpression → BuildRegularExpression → ConvertToRegularExpression. When the malformed bracket expression is encountered, ThrowInvalidRegex is called with an out-of-bounds pointer into globPattern.
  4. Achieve denial of service: The application reads past the end of the globPattern buffer, triggering a crash (ASAN: heap-use-after-free/out-of-bounds read in strlen), resulting in application termination (GitHub Issue #2228, Patch Commit).

Indicators of compromise

  • Logs: Application crash logs or core dumps referencing OpenColorIO::ThrowInvalidRegex, ConvertToRegularExpression, or FileRules.cpp at line 55; ASAN output reporting heap-use-after-free or out-of-bounds read in strlen within the OpenColorIO process.
  • File System: Presence of unexpected or externally supplied YAML configuration files with malformed FileRules sections containing unmatched bracket expressions in glob patterns.
  • Process: Abnormal termination (crash/abort) of processes loading OpenColorIO configurations, particularly those invoking Config::CreateFromStream or OCIOYaml::Read with user-supplied input (GitHub Issue #2228).

Mitigation and workarounds

Upgrade AcademySoftwareFoundation OpenColorIO to version 2.5.1 or later, which includes the fix from commit ebdbb75123c9d5f4643e041314e2bc988a13f20d merged on January 11, 2026. Affected versions include 2.0, 2.1, 2.2, 2.3, 2.4, and 2.5.0. As a workaround where upgrading is not immediately possible, restrict local user access to OpenColorIO configuration files and avoid loading untrusted YAML configs containing FileRules sections (GitHub Advisory, GitHub Milestone).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

opencolorio

Affected

sid

opencolorio

Affected

trixie

opencolorio

Affected

Ubuntu

Unknown

bionic (esm-apps)

opencolorio

Unknown

devel

opencolorio

Unknown

focal (esm-apps)

opencolorio

Unknown

jammy

opencolorio

Unknown

jammy (esm-apps)

opencolorio

Unknown

noble

opencolorio

Unknown

noble (esm-apps)

opencolorio

Unknown

resolute

opencolorio

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management