PT-2026-95451 · Unknown · Openimageio

·

CVE-2026-59156

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenImageIO versions prior to 3.0.20.0 OpenImageIO versions prior to 3.1.15.0 OpenImageIO versions prior to 3.2.0.3-beta1
Description A crafted FITS stream containing consecutive 2880-byte header blocks without the mandatory END keyword causes the read fits header() function to call itself recursively without a depth bound. This repeated recursive parsing exhausts the application stack, leading to a denial of service. The issue is located in src/fits.imageio/fitsinput.cpp within the FitsInput::read fits header() function.
Recommendations Update to version 3.0.20.0. Update to version 3.1.15.0. Update to version 3.2.0.3-beta1.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59156
GHSA-XVWR-X6CH-V2FQ

Affected Products

Openimageio