Junglewise Threat Intelligence

CVE-2026-59156: OpenImageIO stack overflow in FITS header parsing

CVE-2026-59156 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a toolset for reading and manipulating image files used in VFX and animation production. A crafted FITS image file with excessive header blocks can trigger a stack overflow in the parsing code, causing the application to crash and resulting in denial of service for any workflow processing untrusted FITS files.

Technical details

The vulnerability is a stack overflow caused by unbounded recursion in FitsInput::read_fits_header() when parsing FITS files with many consecutive 2880-byte header blocks lacking the mandatory END keyword. An attacker can supply a malicious FITS file that exhausts the application stack through recursive parsing calls. The fix converts the recursive implementation to an iterative loop with a maximum limit of 10,000 header blocks.

Affected products

  • Academy Software Foundation OpenImageIO before 3.0.20.0, before 3.1.15.0, before 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed
  • 2026-06-20: patched: Fix committed to main branch

References

Related threats