{"api_version":"v1","generated_at":"2026-10-08T17:35:00+00:00","product":{"cve_count":19,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-publisher-not-identified-openexr-e1bb4b6516ec","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/openexr","name":"openexr","next_cursor":null,"observations":[{"affected":"Fixed in OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-20304","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20304","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.947Z","patch_url":"https://github.com/AcademySoftwareFoundation/openexr/pull/849","primary_source":"","published":"2022-08-23T00:00:00.000Z"},{"affected":"Fixed in OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-20298","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20298","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.785Z","patch_url":"https://github.com/AcademySoftwareFoundation/openexr/pull/843","primary_source":"","published":"2022-08-23T00:00:00.000Z"},{"affected":"OpenEXR 3.1.2","affected_versions_present":true,"cve_id":"CVE-2021-3941","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3941","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:09:09.632Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=2019789","primary_source":"","published":"2022-03-25T00:00:00.000Z"},{"affected":"OpenEXR 3.1.2","affected_versions_present":true,"cve_id":"CVE-2021-3933","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3933","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T17:09:09.619Z","patch_url":"","primary_source":"","published":"2022-03-25T00:00:00.000Z"},{"affected":"Affected before v2.5.4","affected_versions_present":true,"cve_id":"CVE-2021-20299","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20299","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.881Z","patch_url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25740","primary_source":"","published":"2022-03-16T00:00:00.000Z"},{"affected":"Fixed in v2.5.4 and beyond.","affected_versions_present":true,"cve_id":"CVE-2021-20303","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20303","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.668Z","patch_url":"https://github.com/AcademySoftwareFoundation/openexr/pull/831","primary_source":"","published":"2022-03-04T00:00:00.000Z"},{"affected":"Fixed in v2.5.4 and beyond.","affected_versions_present":true,"cve_id":"CVE-2021-20302","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20302","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.828Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939161","primary_source":"","published":"2022-03-04T00:00:00.000Z"},{"affected":"Fixed in v2.5.4 and beyond.","affected_versions_present":true,"cve_id":"CVE-2021-20300","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20300","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.704Z","patch_url":"https://github.com/AcademySoftwareFoundation/openexr/pull/836","primary_source":"","published":"2022-03-04T00:00:00.000Z"},{"affected":"OpenEXR 3.0.5","affected_versions_present":true,"cve_id":"CVE-2021-3605","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3605","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:01:07.535Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1970991","primary_source":"","published":"2021-08-25T00:00:00.000Z"},{"affected":"OpenEXR 3.0.5","affected_versions_present":true,"cve_id":"CVE-2021-3598","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3598","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:01:08.004Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1970987","primary_source":"","published":"2021-07-06T00:00:00.000Z"},{"affected":"OpenEXR 3.0.1","affected_versions_present":true,"cve_id":"CVE-2021-26945","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-26945","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T20:33:41.491Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1947591","primary_source":"","published":"2021-06-08T11:39:06.000Z"},{"affected":"OpenEXR 3.0.1","affected_versions_present":true,"cve_id":"CVE-2021-26260","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-26260","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T20:19:20.135Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1947582","primary_source":"","published":"2021-06-08T00:00:00.000Z"},{"affected":"OpenEXR 3.0.1","affected_versions_present":true,"cve_id":"CVE-2021-23215","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-23215","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T19:05:53.906Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1947586","primary_source":"","published":"2021-06-08T00:00:00.000Z"},{"affected":"OpenEXR 3.0.1","affected_versions_present":true,"cve_id":"CVE-2021-23169","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-23169","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T19:05:53.909Z","patch_url":"","primary_source":"","published":"2021-06-08T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-20296","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-20296","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T17:37:23.528Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939141","primary_source":"","published":"2021-04-01T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3479","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3479","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.634Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939149","primary_source":"","published":"2021-03-31T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3478","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3478","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.620Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939160","primary_source":"","published":"2021-03-31T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3477","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3477","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.607Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939159","primary_source":"","published":"2021-03-31T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3476","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3476","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.728Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939145","primary_source":"","published":"2021-03-30T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3475","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3475","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.515Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939144","primary_source":"","published":"2021-03-30T00:00:00.000Z"},{"affected":"OpenEXR 3.0.0-beta","affected_versions_present":true,"cve_id":"CVE-2021-3474","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3474","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T16:53:17.593Z","patch_url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939142","primary_source":"","published":"2021-03-30T00:00:00.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Publisher not identified"}}
