CVE Feed

    Dashboard / CVE / CVE-2026-2704

    CVE-2026-2704

    A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.0 is sufficient to fix this issue. The identifier of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is suggested to install a patch to address this issue.

    Published:Feb 19, 2026
    Last Modified:May 28, 2026
    EPS:Feb 19, 2026
    EPSS Score:0.00037
    CVSS Score:4.3

    Affected Products

    Vendor
    Open Babel
    Product
    Open Babel
    Vendor
    Openbabel
    Product
    Open Babel

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High