{"id":"ECHO-3812-47cc-7fc2","summary":"Signed integer overflow in undo_pxr24_impl() in the OpenEXRCore\nPXR24 decoder. Vulnerability introduced in 3.2.0; the affected\ncore PXR24 decoder does not exist in 3.1.x.\n","modified":"2026-09-15T03:33:45.912699266Z","published":"2026-06-01T07:39:17.593Z","withdrawn":"2026-06-01T13:30:03.694Z","upstream":["CVE-2026-34380"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-34380"}],"affected":[{"package":{"name":"openexr","ecosystem":"Echo","purl":"pkg:deb/echo/openexr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.13-2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-3812-47cc-7fc2.json"}}],"schema_version":"1.9.0"}