OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.
Cite this page
CVE-2025-48074. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-48074
Use CWE-770, Openexr vendor hub and Openexr product page to widen CVE-2025-48074 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34543, CVE-2026-34588 and CVE-2026-40250 for nearby disclosures in the same product family.