Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55j6-rjhx-hwfh

Опубликовано: 01 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

Summary

A memory-safety vulnerability in Open Babel's CACAO parser caused a NULL pointer dereference when reading a crafted input file.

Details

The flaw was in CacaoFormat::SetHilderbrandt. A malformed input caused the parser to dereference a NULL pointer while applying the Hilderbrandt transformation.

Impact

Open Babel is a C++ library and CLI used to read and write chemistry file formats; it is shipped by Linux distributions and embedded in services that may parse untrusted input. Triggering this vulnerability requires the victim to open a malicious CACAO file with the obabel tool, the OBConversion API, or any of the language bindings (Python, Ruby, Java, R, Perl, C#, PHP).

Affected versions

All releases up to and including 3.1.1.

Patched version

3.2.0 (released 2026-05-26).

Patch

Fix commit: https://github.com/openbabel/openbabel/commit/ecaed96f Originally reported as #2827; fixes consolidated in #2913.

A minimized reproducer for this CVE is checked in under test/files/fuzz_regress/ and is exercised on every CI build under ASAN+UBSAN by the fuzzregresstest harness.

Credit

Reported via OSS-Fuzz.

Пакеты

Наименование

openbabel

pip
Затронутые версииВерсия исправления

< 3.2.0

3.2.0

EPSS

Процентиль: 9%
0.00188
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-404
CWE-476

Связанные уязвимости

CVSS3: 3.3
ubuntu
10 месяцев назад

A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt of the file /src/formats/cacaoformat.cpp. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been made public and could be used.

CVSS3: 3.3
nvd
10 месяцев назад

A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt of the file /src/formats/cacaoformat.cpp. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been made public and could be used.

CVSS3: 3.3
debian
10 месяцев назад

A vulnerability was found in Open Babel up to 3.1.1. The impacted elem ...

CVSS3: 5.5
fstec
10 месяцев назад

Уязвимость функции CacaoFormat::SetHilderbrandt программного обеспечения преобразования форматов файлов химических веществ Open Babel, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.8
redos
9 месяцев назад

Множественные уязвимости xdrawchem

EPSS

Процентиль: 9%
0.00188
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-404
CWE-476