Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte header blocks without the mandatory end keyword makes fitsinput::read_fits_header() call itself without a depth bound. repeated recursive parsing exhausts the application stack, resulting in denial of service. The affected implementation is identified by src/fits.imageio/fitsinput.cpp, FitsInput::read_fits_header(), END keyword, and 2880-byte FITS header blocks, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via stack overflow
Action: Patch ASAP
AI Analysis

Impact

OpenImageIO can perform unbounded recursion when parsing FITS headers that contain consecutive 2880‑byte blocks without the required END keyword. The recursive call to fitsinput::read_fits_header() has no depth bound, causing the application stack to be exhausted and the process to terminate. This flaw is formally categorized as CWE‑674 and results in a denial of service rather than information disclosure or privilege escalation.

Affected Systems

The vulnerability affects the Academy Software Foundation’s OpenImageIO toolset, which is used to read, write, and manipulate image files in VFX and animation pipelines. Versions before the releases 3.0.20.0, 3.1.15.0, and 3.2.0.3‑beta1 are impacted. These releases contain the parser bug in src/fits.imageio/fitsinput.cpp, specifically within the FitsInput::read_fits_header() function that processes FITS header blocks.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate impact. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not a known exploited vulnerability. The likely attack vector involves supplying a crafted FITS file to a vulnerable consumer of OpenImageIO, such as a VFX rendering pipeline or image conversion tool. Successful exploitation would result in a process crash or loss of service for the affected application, with the impact limited to denial of service but with significant operational impact in production environments.

Generated by OpenCVE AI on September 19, 2026 at 18:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to version 3.0.20.0, 3.1.15.0, or 3.2.0.3‑beta1 where the recursive parsing is fixed.
  • Replace or isolate any components that consume OpenImageIO during the upgrade to prevent accidental execution of vulnerable code.
  • Validate FITS files before processing by ensuring the END keyword is present and rejecting any files with too many consecutive 2880‑byte blocks as a temporary mitigation.

Generated by OpenCVE AI on September 19, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte header blocks without the mandatory end keyword makes fitsinput::read_fits_header() call itself without a depth bound. repeated recursive parsing exhausts the application stack, resulting in denial of service. The affected implementation is identified by src/fits.imageio/fitsinput.cpp, FitsInput::read_fits_header(), END keyword, and 2880-byte FITS header blocks, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Title OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:49.717Z

Reserved: 2026-07-02T16:50:27.887Z

Link: CVE-2026-59156

cve-icon Vulnrichment

Updated: 2026-09-24T20:55:45.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:06.980

Modified: 2026-09-29T18:57:22.510

Link: CVE-2026-59156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses