CVE-2026-3408

MEDIUM

Open Babel <=3.1.1 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is best practice to apply a patch to resolve this issue.

References (7)

Core 7
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.348303
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.348303
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.763756
Issue Tracking issue-tracking patch
https://github.com/openbabel/openbabel/pull/2862

Scores

CVSS v3 4.3
EPSS 0.0038
EPSS Percentile 29.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476 CWE-787
Status published
Products (1)
openbabel/open_babel < 3.1.1
Published Mar 02, 2026
Tracked Since Mar 02, 2026