CVE-2026-34543: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34543 is a heap information disclosure vulnerability in OpenEXR's PXR24 decompression implementation, classified as "Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)." It affects OpenEXR versions 3.2.0–3.2.6, 3.3.0–3.3.8, and 3.4.0–3.4.7. The vulnerability was published on March 27, 2026, and patched in versions 3.2.7, 3.3.9, and 3.4.8. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, OpenEXR Advisory).

Technical details

The vulnerability (CWE-908: Use of Uninitialized Resource) arises from two compounding flaws in OpenEXR's PXR24 decompression path. First, in compression.c (lines 202–205), the exr_uncompress_buffer() function treats LIBDEFLATE_SHORT_OUTPUT — a condition where the zlib stream decompresses to fewer bytes than the output buffer — as a success rather than an error, writing the actual byte count to actual_out but returning EXR_ERR_SUCCESS. Second, in internal_pxr24.c, the undo_pxr24_impl() function (lines 261–399) ignores the returned outSize value and instead reads from the scratch buffer based solely on uncompressed_size derived from the file's header metadata. An attacker can craft a PXR24 EXR file with a valid but truncated zlib stream, causing the decoder to read uninitialized heap memory in the region between outSize and uncompressed_size and incorporate it into the output pixel data. A proof-of-concept with reproducible steps is publicly available (OpenEXR Advisory, Patch Commit).

Impact

Successful exploitation results in a high-confidentiality-impact information disclosure: sensitive heap memory contents are leaked through the decoded pixel data of the processed EXR image. No integrity or availability impact is associated with this vulnerability. The attack requires no authentication, no privileges, and no user interaction beyond the application reading a malicious EXR file, making it exploitable in any context where untrusted EXR files are processed — including media pipelines, rendering services, and image viewers (Github Advisory, OpenEXR Advisory).

Exploitability

A proof-of-concept exploit is publicly available via the official security advisory, with concrete, reproducible steps using a Docker-based environment to demonstrate heap memory leakage (OpenEXR Advisory). Feedly threat intelligence rates the PoC confidence as high, noting the advisory provides step-by-step reproduction instructions. The EPSS score is approximately 0.04% (0.000400), indicating a low current probability of active exploitation. There is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion at this time (Github Advisory).

Exploitation steps

  1. Craft a malicious EXR file: Create a PXR24-compressed EXR file containing a valid but intentionally truncated zlib stream. The compressed data must decompress successfully but produce fewer bytes than the uncompressed_size declared in the file's header metadata.
  2. Deliver the file to the target: Provide the malicious EXR file to any application or service that uses a vulnerable version of OpenEXR (3.2.0–3.2.6, 3.3.0–3.3.8, or 3.4.0–3.4.7) to read or process EXR images. No user interaction beyond the application opening the file is required.
  3. Trigger decompression: When the application reads the file, exr_uncompress_buffer() decompresses the truncated zlib stream, receives LIBDEFLATE_SHORT_OUTPUT, and incorrectly returns EXR_ERR_SUCCESS with outSize less than uncompressed_size.
  4. Heap memory is read: The undo_pxr24_impl() function ignores outSize and reads the scratch buffer up to uncompressed_size, incorporating uninitialized heap memory into the decoded pixel data.
  5. Exfiltrate leaked data: The attacker retrieves the output pixel data (e.g., the rendered/decoded image), which contains heap memory contents that may include sensitive information such as cryptographic keys, credentials, or other in-memory data (OpenEXR Advisory).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .exr files using PXR24 compression in directories processed by OpenEXR-based applications; output image files with anomalous pixel data patterns inconsistent with the expected image content.
  • Network: Inbound delivery of PXR24-compressed EXR files from untrusted or external sources to image processing services; outbound transmission of decoded image data that may contain embedded heap artifacts.
  • Logs: Application logs showing EXR file processing errors or unexpected behavior when handling specific files; crash reports or memory sanitizer output (e.g., from AddressSanitizer/Valgrind) indicating reads of uninitialized memory during PXR24 decompression.

Mitigation and workarounds

Upgrade OpenEXR to a patched version: 3.4.8 (for the 3.4.x branch), 3.3.9 (for the 3.3.x branch), or 3.2.7 (for the 3.2.x branch). The fix validates that outSize matches the expected packed payload size after decompression and rejects chunks where these values differ (Patch Commit, v3.4.8 Release). As a workaround where upgrading is not immediately feasible, restrict EXR file processing to trusted, internally generated sources and avoid processing externally supplied PXR24-compressed EXR files (Github Advisory).

Community reactions

The vulnerability was disclosed by the Academy Software Foundation (ACSF) through GitHub's security advisory system. The openSUSE security team issued a security announcement addressing the issue for their distributions (openSUSE Announcement). No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

openexr

Affected

sid

openexr: 3.4.14-0.1

Fixed

trixie

openexr

Affected

Ubuntu

Affected

bionic (esm-infra)

openexr

Not Affected

devel

openexr

Affected

focal (esm-apps)

openexr

Not Affected

jammy

openexr

Not Affected

jammy (esm-apps)

openexr

Not Affected

noble

openexr

Not Affected

noble (esm-apps)

openexr

Not Affected

questing

openexr

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

OpenEXR.src

Affected

Alpine

Fixed

edge

openexr: 3.4.10-r0

Fixed

v3.22

openexr: 3.3.11-r0

Fixed

v3.23

openexr: 3.4.13-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management