Опубликовано: 19 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 4.3
Описание
Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4w5w-4fhm-q483. This link is maintained to preserve external references.
Original Description
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-2705
- https://github.com/openbabel/openbabel/issues/2848
- https://github.com/openbabel/openbabel/pull/2862
- https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a
- https://github.com/oneafter/0128/blob/main/ob2/repro.mol2
- https://vuldb.com/?ctiid.346651
- https://vuldb.com/?id.346651
- https://vuldb.com/?submit.754379
Пакеты
Наименование
openbabel
pip
Затронутые версииВерсия исправления
< 3.2.0
3.2.0
2.1 Low
CVSS4
4.3 Medium
CVSS3
Дефекты
CWE-119
2.1 Low
CVSS4
4.3 Medium
CVSS3
Дефекты
CWE-119