{"schema_version":1,"title":"Academy Software Foundation vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in Academy Software Foundation: 1 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88384, was published on 24 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/academy-software-foundation","json_url":"https://junglewise.ai/threats/vendors/academy-software-foundation.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/academy-software-foundation","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":12,"all_time":24,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":13,"last_90_days":14,"last_365_days":24},"latest":[{"cve":"CVE-2026-88384","cvss":5.5,"epss":0.0019,"slug":"cve-2026-88384-openexr-3-4-14-contains-a-null-pointer-dereference-in-the-c","title":"OpenEXR null pointer dereference in attribute parsing","severity":"medium","exploited":false,"published_at":"2026-09-24T17:17:07.907+00:00","url":"https://junglewise.ai/threats/cve-2026-88384-openexr-3-4-14-contains-a-null-pointer-dereference-in-the-c"},{"cve":"CVE-2026-67549","cvss":7.6,"epss":0.0038,"slug":"cve-2026-67549-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap overflow in TIFF CMYK decoding","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:08.733+00:00","url":"https://junglewise.ai/threats/cve-2026-67549-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-65970","cvss":5.3,"epss":0.004,"slug":"cve-2026-65970-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO use-after-scope in multithreaded TIFF decompression","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:08.59+00:00","url":"https://junglewise.ai/threats/cve-2026-65970-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-65969","cvss":5.5,"epss":0.0017,"slug":"cve-2026-65969-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO integer overflow in GIF palette splitting","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:08.433+00:00","url":"https://junglewise.ai/threats/cve-2026-65969-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63638","cvss":8.3,"epss":0.0045,"slug":"cve-2026-63638-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap overflow in cineon image parsing","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:08.283+00:00","url":"https://junglewise.ai/threats/cve-2026-63638-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63635","cvss":5.5,"epss":0.002,"slug":"cve-2026-63635-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO out-of-bounds read in PSD parser","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:08.13+00:00","url":"https://junglewise.ai/threats/cve-2026-63635-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63422","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63422-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap overflow in OpenEXR partial tile reading","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:07.987+00:00","url":"https://junglewise.ai/threats/cve-2026-63422-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63420","cvss":5.5,"epss":0.0017,"slug":"cve-2026-63420-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap out-of-bounds read in PSD processing","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:07.837+00:00","url":"https://junglewise.ai/threats/cve-2026-63420-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63419","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63419-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap out-of-bounds write in IFF decoder","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:07.687+00:00","url":"https://junglewise.ai/threats/cve-2026-63419-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-59956","cvss":6.1,"epss":0.0017,"slug":"cve-2026-59956-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap buffer over-read in IFF image parsing","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:07.29+00:00","url":"https://junglewise.ai/threats/cve-2026-59956-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-59181","cvss":6.1,"epss":0.0017,"slug":"cve-2026-59181-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO buffer overflow in Cineon image parsing","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:07.137+00:00","url":"https://junglewise.ai/threats/cve-2026-59181-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-59156","cvss":6.5,"epss":0.004,"slug":"cve-2026-59156-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO stack overflow in FITS header parsing","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:06.98+00:00","url":"https://junglewise.ai/threats/cve-2026-59156-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-50291","cvss":5.5,"epss":0.002,"slug":"cve-2026-50291-openimageio-bmp-palette-denial-of-service","title":"OpenImageIO BMP palette denial of service","severity":"medium","exploited":false,"published_at":"2026-09-17T22:16:59.45+00:00","url":"https://junglewise.ai/threats/cve-2026-50291-openimageio-bmp-palette-denial-of-service"},{"cve":"CVE-2025-64181","cvss":3.1,"epss":0.0038,"slug":"cve-2025-64181-openexr-use-of-uninitialized-memory-in-generic-unpack","title":"PYSEC-2026-2843 - OpenEXR Makes Use of Uninitialized Memory","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:48.278249+00:00","url":"https://junglewise.ai/threats/cve-2025-64181-openexr-use-of-uninitialized-memory-in-generic-unpack"},{"cve":"CVE-2026-42450","cvss":8.4,"slug":"cve-2026-42450-opencolorio-stack-buffer-overflow-in-spi3d-lut-parser","title":"OpenColorIO stack buffer overflow in Spi3D LUT parser","severity":"info","exploited":false,"published_at":"2026-06-24T14:17:31.19+00:00","url":"https://junglewise.ai/threats/cve-2026-42450-opencolorio-stack-buffer-overflow-in-spi3d-lut-parser"},{"cve":"CVE-2026-43996","cvss":5.5,"epss":0.0001,"slug":"cve-2026-43996-openimageio-out-of-bounds-read-in-tgainput-decode-pixel","title":"OpenImageIO out-of-bounds read in TGAInput decode_pixel","severity":"medium","exploited":false,"published_at":"2026-05-14T20:17:07.3+00:00","url":"https://junglewise.ai/threats/cve-2026-43996-openimageio-out-of-bounds-read-in-tgainput-decode-pixel"},{"cve":"CVE-2026-43909","cvss":8.8,"epss":0.0004,"slug":"cve-2026-43909-openimageio-integer-overflow-in-swaprgbabytes-dpx-decoder","title":"OpenImageIO integer overflow in SwapRGBABytes DPX decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:07.063+00:00","url":"https://junglewise.ai/threats/cve-2026-43909-openimageio-integer-overflow-in-swaprgbabytes-dpx-decoder"},{"cve":"CVE-2026-43908","cvss":8.8,"epss":0.0004,"slug":"cve-2026-43908-openimageio-integer-overflow-in-convertcbycrytorgb","title":"OpenImageIO integer overflow in ConvertCbYCrYToRGB","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.92+00:00","url":"https://junglewise.ai/threats/cve-2026-43908-openimageio-integer-overflow-in-convertcbycrytorgb"},{"cve":"CVE-2026-43907","cvss":8.3,"epss":0.0004,"slug":"cve-2026-43907-openimageio-heap-overflow-in-dpx-decoder","title":"OpenImageIO heap overflow in DPX decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.76+00:00","url":"https://junglewise.ai/threats/cve-2026-43907-openimageio-heap-overflow-in-dpx-decoder"},{"cve":"CVE-2026-43906","cvss":7.8,"epss":0.0002,"slug":"cve-2026-43906-openimageio-heap-buffer-overflow-in-heif-decoder","title":"OpenImageIO heap buffer overflow in HEIF decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.607+00:00","url":"https://junglewise.ai/threats/cve-2026-43906-openimageio-heap-buffer-overflow-in-heif-decoder"},{"cve":"CVE-2026-43905","cvss":7.8,"epss":0.0001,"slug":"cve-2026-43905-openimageio-heap-overflow-in-jpeg2000-reader","title":"OpenImageIO heap overflow in JPEG2000 reader","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.447+00:00","url":"https://junglewise.ai/threats/cve-2026-43905-openimageio-heap-overflow-in-jpeg2000-reader"},{"cve":"CVE-2026-43904","cvss":7.8,"epss":0.0001,"slug":"cve-2026-43904-openimageio-heap-overflow-in-softimage-pic-rle-decoder","title":"OpenImageIO heap overflow in Softimage PIC RLE decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.24+00:00","url":"https://junglewise.ai/threats/cve-2026-43904-openimageio-heap-overflow-in-softimage-pic-rle-decoder"},{"cve":"CVE-2026-43903","cvss":7.8,"epss":0.0001,"slug":"cve-2026-43903-openimageio-heap-buffer-overflow-in-sgi-rle-decoder","title":"OpenImageIO heap buffer overflow in SGI RLE decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.077+00:00","url":"https://junglewise.ai/threats/cve-2026-43903-openimageio-heap-buffer-overflow-in-sgi-rle-decoder"},{"cve":"CVE-2026-27622","cvss":7.8,"epss":0.0021,"slug":"cve-2026-27622-openexr-heap-out-of-bounds-write-in-compositedeepscanline","title":"OpenEXR heap out-of-bounds write in CompositeDeepScanLine","severity":"high","exploited":false,"published_at":"2026-03-03T23:15:55.737+00:00","url":"https://junglewise.ai/threats/cve-2026-27622-openexr-heap-out-of-bounds-write-in-compositedeepscanline"}],"vendor":{"hub":true,"name":"Academy Software Foundation","slug":"academy-software-foundation","homepage":"https://www.aswf.io/","description":"The Academy Software Foundation provides a neutral forum for open source software developers in the motion picture and broader media industries to share resources and collaborate on technologies.","url":"https://junglewise.ai/threats/vendors/academy-software-foundation"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-43909","cvss":8.8,"epss":0.0004,"slug":"cve-2026-43909-openimageio-integer-overflow-in-swaprgbabytes-dpx-decoder","title":"OpenImageIO integer overflow in SwapRGBABytes DPX decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:07.063+00:00","url":"https://junglewise.ai/threats/cve-2026-43909-openimageio-integer-overflow-in-swaprgbabytes-dpx-decoder"},{"cve":"CVE-2026-43908","cvss":8.8,"epss":0.0004,"slug":"cve-2026-43908-openimageio-integer-overflow-in-convertcbycrytorgb","title":"OpenImageIO integer overflow in ConvertCbYCrYToRGB","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.92+00:00","url":"https://junglewise.ai/threats/cve-2026-43908-openimageio-integer-overflow-in-convertcbycrytorgb"},{"cve":"CVE-2026-63638","cvss":8.3,"epss":0.0045,"slug":"cve-2026-63638-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap overflow in cineon image parsing","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:08.283+00:00","url":"https://junglewise.ai/threats/cve-2026-63638-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-43907","cvss":8.3,"epss":0.0004,"slug":"cve-2026-43907-openimageio-heap-overflow-in-dpx-decoder","title":"OpenImageIO heap overflow in DPX decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.76+00:00","url":"https://junglewise.ai/threats/cve-2026-43907-openimageio-heap-overflow-in-dpx-decoder"},{"cve":"CVE-2026-27622","cvss":7.8,"epss":0.0021,"slug":"cve-2026-27622-openexr-heap-out-of-bounds-write-in-compositedeepscanline","title":"OpenEXR heap out-of-bounds write in CompositeDeepScanLine","severity":"high","exploited":false,"published_at":"2026-03-03T23:15:55.737+00:00","url":"https://junglewise.ai/threats/cve-2026-27622-openexr-heap-out-of-bounds-write-in-compositedeepscanline"},{"cve":"CVE-2026-63422","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63422-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap overflow in OpenEXR partial tile reading","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:07.987+00:00","url":"https://junglewise.ai/threats/cve-2026-63422-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-63419","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63419-openimageio-is-a-toolset-for-reading-writing-and-manipulating","title":"OpenImageIO heap out-of-bounds write in IFF decoder","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:07.687+00:00","url":"https://junglewise.ai/threats/cve-2026-63419-openimageio-is-a-toolset-for-reading-writing-and-manipulating"},{"cve":"CVE-2026-43906","cvss":7.8,"epss":0.0002,"slug":"cve-2026-43906-openimageio-heap-buffer-overflow-in-heif-decoder","title":"OpenImageIO heap buffer overflow in HEIF decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.607+00:00","url":"https://junglewise.ai/threats/cve-2026-43906-openimageio-heap-buffer-overflow-in-heif-decoder"},{"cve":"CVE-2026-43905","cvss":7.8,"epss":0.0001,"slug":"cve-2026-43905-openimageio-heap-overflow-in-jpeg2000-reader","title":"OpenImageIO heap overflow in JPEG2000 reader","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.447+00:00","url":"https://junglewise.ai/threats/cve-2026-43905-openimageio-heap-overflow-in-jpeg2000-reader"},{"cve":"CVE-2026-43904","cvss":7.8,"epss":0.0001,"slug":"cve-2026-43904-openimageio-heap-overflow-in-softimage-pic-rle-decoder","title":"OpenImageIO heap overflow in Softimage PIC RLE decoder","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:06.24+00:00","url":"https://junglewise.ai/threats/cve-2026-43904-openimageio-heap-overflow-in-softimage-pic-rle-decoder"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"Academy Software Foundation OpenImageIO","slug":"openimageio","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/openimageio"},{"name":"Academy Software Foundation OpenEXR","slug":"academy-software-foundation-openexr","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/academy-software-foundation-openexr"}]}