What happened
The OpenEXR project released 3.4.15, 3.3.14 and 3.2.12 on August 21. The release notes say two issues could cause excessive memory allocation when parsing corrupt or malicious IDManifest data. CVE identifiers had been requested but were not yet listed.
The affected behaviour is limited to code that decodes the IDManifest attribute; the project says other OpenEXR code is not affected even when an image contains that attribute. Version 3.4.15 also carries Windows export and compiler-warning fixes.
Why it matters
This is an availability and resource-exhaustion problem in a defined decoder path, not evidence of universal EXR compromise or remote code execution. Studios should map the library through renderers, ingest tools and asset services before deciding where untrusted files can reach the vulnerable code.
What we're watching
We are watching CVE assignment and downstream packages in VFX, DCC and render-farm tooling. Teams that do not decode IDManifest are outside the stated affected path, but should still verify rather than assume their build configuration.