Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j35x-w4gj-pf7w

Опубликовано: 30 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

Summary

A memory-safety vulnerability in Open Babel's SMILES parser caused a heap buffer overflow when reading a crafted input string.

Details

The flaw was in OBSmilesParser::ParseSmiles. A malformed SMILES input caused the parser to write past the end of a heap-allocated buffer.

Impact

Open Babel is a C++ library and CLI used to read and write chemistry file formats; it is shipped by Linux distributions and embedded in services that may parse untrusted input. Triggering this vulnerability requires the victim to parse a malicious SMILES string with the obabel tool, the OBConversion API, or any of the language bindings (Python, Ruby, Java, R, Perl, C#, PHP). SMILES strings are commonly passed on the command line and through scripted pipelines, so this primitive is especially reachable.

Affected versions

All releases up to and including 3.1.1.

Patched version

3.2.0 (released 2026-05-26).

Patch

Fix commit: https://github.com/openbabel/openbabel/commit/b34cd604 Originally reported as #2831; fixes consolidated in #2913.

A minimized reproducer for this CVE is checked in under test/files/fuzz_regress/ and is exercised on every CI build under ASAN+UBSAN by the fuzzregresstest harness.

Credit

Reported via OSS-Fuzz.

Пакеты

Наименование

openbabel

pip
Затронутые версииВерсия исправления

< 3.2.0

3.2.0

EPSS

Процентиль: 17%
0.00258
Низкий

7.8 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of the file /src/formats/smilesformat.cpp. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit is now public and may be used.

CVSS3: 5.3
nvd
10 месяцев назад

A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of the file /src/formats/smilesformat.cpp. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit is now public and may be used.

CVSS3: 5.3
debian
10 месяцев назад

A vulnerability was detected in Open Babel up to 3.1.1. This issue aff ...

CVSS3: 7.8
fstec
10 месяцев назад

Уязвимость функции ChemKinFormat::CheckSpecies программного обеспечения преобразования форматов файлов химических веществ Open Babel, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.8
redos
9 месяцев назад

Множественные уязвимости xdrawchem

EPSS

Процентиль: 17%
0.00258
Низкий

7.8 High

CVSS3

Дефекты

CWE-119