Junglewise Threat Intelligence

CVE-2026-63420: OpenImageIO heap out-of-bounds read in PSD processing

CVE-2026-63420 · Severity: medium · CVSS 5.5 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a tool for reading and writing image files used in VFX and animation workflows. When processing Photoshop (PSD) files with transparency metadata and certain options enabled, the software can crash due to an out-of-bounds memory access, causing denial of service to applications that depend on it.

Technical details

A heap out-of-bounds read occurs in PSDInput::read_native_scanline() when processing indexed PSD files with transparency, triggered when the oiio:rawcolor or psd:rawdata options are enabled. The vulnerability arises because the number of stored channel buffers is fewer than the spec.nchannels value advertised, causing array indexing to exceed allocated memory. The issue can be triggered by opening a maliciously crafted PSD file.

Affected products

  • Academy Software Foundation OpenImageIO prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed: CVE-2026-63420 published
  • 2026-07-11: patched: Fix merged in commit 4995b25 to guard row interleave bounds on corrupt data

References

Related threats