Junglewise Threat Intelligence

CVE-2026-65970: OpenImageIO use-after-scope in multithreaded TIFF decompression

CVE-2026-65970 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a media processing library used in animation and VFX workflows to read and manipulate image files. A crafted ZIP-compressed TIFF file processed with multithreading enabled can cause the application to crash, disrupting production pipelines and affecting availability of rendering or compositing services.

Technical details

A use-after-scope vulnerability exists in the TIFF input handler's multithreaded scanline decompression path. When TIFFInput::read_native_scanlines() exits early on certain error conditions, background worker tasks attempt to access stack variables (ok and compressed_scratch) after they have been destroyed, resulting in a denial of service crash. The vulnerability requires TIFF multithreading to be enabled and a specially crafted compressed TIFF file as input.

Affected products

  • Academy Software Foundation OpenImageIO prior to 3.1.16.0

Timeline

  • 2026-09-18: disclosed
  • 2026-07-04: patched: Fix merged to main branch

References

Related threats