{"id":"ECHO-71a9-4d38-b645","summary":"Integer overflow in the HTJ2K decoder (ht_undo_impl) leading to a\nheap-buffer-overflow. HTJ2K support (OpenEXRCore internal_ht.cpp /\nht_undo_impl) was added in 3.4.0; affected range is 3.4.0-3.4.11.\nThe codec does not exist in 3.1.x, so 3.1.13 is not affected\n(Debian reports only a fixed_version, not the affected range).\n","modified":"2026-09-15T03:33:46.110081055Z","published":"2026-06-21T17:25:33.561Z","withdrawn":"2026-06-24T18:00:04.378Z","upstream":["CVE-2026-44663"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-44663"}],"affected":[{"package":{"name":"openexr","ecosystem":"Echo","purl":"pkg:deb/echo/openexr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.13-2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-71a9-4d38-b645.json"}}],"schema_version":"1.9.0"}