PT-2026-20643 · Open Babel · Open Babel

·

CVE-2026-2704

·

Published

2026-01-01

·

Updated

2026-07-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open Babel versions prior to 3.1.2
Description A security issue exists in Open Babel up to version 3.1.1. The issue involves an out-of-bounds read within the OpenBabel::transform3d::DescribeAsString function located in the src/math/transform3d.cpp file, specifically within the CIF File Handler component. This issue is remotely exploitable and has been publicly disclosed. The project was notified of the problem but has not yet responded.
Recommendations Update to version 3.1.2 or later. As a temporary workaround, consider restricting access to the CIF File Handler component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2704
GHSA-2M54-8M6G-QF93
GHSA-6XW4-2G22-26H8
OPENSUSE-SU-2026:11096-1
OPENSUSE-SU-2026:21190-1
PYSEC-2026-2774

Affected Products

Open Babel