Skip to content

[automatic] Publish 8 advisories for OpenImageIO_jll#516

Open
jlsec-bot wants to merge 1 commit into
JuliaLang:mainfrom
jlsec-bot:OpenImageIO_jll
Open

[automatic] Publish 8 advisories for OpenImageIO_jll#516
jlsec-bot wants to merge 1 commit into
JuliaLang:mainfrom
jlsec-bot:OpenImageIO_jll

Conversation

@jlsec-bot

Copy link
Copy Markdown
Contributor

This action searched 22 packages for advisories that pertain here. It identified 8 advisories as being related to the Julia package(s): OpenImageIO_jll.

⚠ There are 8 advisories with unbounded vulnerabilities

The publication of unbounded advisories is significantly more impactful and, if at all possible, should be addressed in the packages directly

8 advisories affect artifacts provided by OpenImageIO_jll

These identifications depend upon accurately tracked artifact metadata in GeneralMetadata.jl. Packages are only listed as affected if they have such tracking, and the vulnerable status (and version numbers themselves) are highly dependent on the accuracy of this metadata. Improvements can be made directly to GeneralMetadata.jl; it is automatically populated on a best-effort basis and manual edits are preserved.

Package and upstream project information

Advisory summaries

  • JLSEC-0000-CVE-2026-43903 (from: CVE-2026-43903) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, and >= 3.1.4.0, < 3.1.13.0, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43904 (from: CVE-2026-43904) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, and >= 3.1.4.0, < 3.1.13.0, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43905 (from: CVE-2026-43905) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, and >= 3.1.4.0, < 3.1.13.0, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43906 (from: CVE-2026-43906) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, >= 3.1.4.0, < 3.1.13.0, and = 3.2.0.2-dev, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43907 (from: CVE-2026-43907) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, >= 3.1.4.0, < 3.1.13.0, and = 3.2.0.2-dev, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43908 (from: CVE-2026-43908) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, >= 3.1.4.0, < 3.1.13.0, = 3.2.0.0-dev, and = 3.2.0.2-dev, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43909 (from: CVE-2026-43909) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, >= 3.1.4.0, < 3.1.13.0, = 3.2.0.0-dev, and = 3.2.0.2-dev, mapping to
      • OpenImageIO_jll at versions: *
  • JLSEC-0000-CVE-2026-43996 (from: CVE-2026-43996) for upstream project(s):

    • openimageio:openimageio at versions: < 3.0.18.0, >= 3.1.0.0, < 3.1.13.0, = 3.2.0.0-dev, and = 3.2.0.2-dev, mapping to
      • OpenImageIO_jll at versions: *

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants