Junglewise Threat Intelligence

CVE-2026-63635: OpenImageIO out-of-bounds read in PSD parser

CVE-2026-63635 · Severity: medium · CVSS 5.5 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a library used in animation and VFX production to read and write image files. A flaw in its PSD (Photoshop) file parser allows an attacker to craft a malicious image file that, when processed with certain options enabled, can cause the application to read memory outside its intended bounds or trigger an unexpected memory allocation, leading to potential denial of service.

Technical details

A crafted PSD file with an invalid color_mode value bypasses validation when the oiio:RawColor or psd:RawData options are enabled, allowing the attacker-controlled value to be used as an index into fixed-size color-mode lookup tables in psdinput::setup(). This results in a global out-of-bounds read and potentially unbounded or bogus memory allocation. The vulnerability is patched by validating the color_mode before the RawColor early return path executes.

Affected products

  • Academy Software Foundation OpenImageIO before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

Timeline

  • 2026-07-04: patched
  • 2026-09-18: disclosed

References

Related threats