PT-2026-22539 · Open Babel · Open Babel

Oneafter

·

Published

2026-03-02

·

Updated

2026-03-02

·

CVE-2026-3408

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open Babel versions up to 3.1.1
Description A flaw exists in Open Babel up to version 3.1.1 related to a null pointer dereference. This issue is located within the OBAtom::GetExplicitValence function in the isrc/atom.cpp file, specifically within the CDXML File Handler component. The issue can be triggered remotely. The exploit is publicly available.
Recommendations Apply the patch e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-3408

Affected Products

Open Babel