<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:39:30.732513+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248901</id>
    <title>EUVD-2026-248901</title>
    <updated>2026-10-02T21:39:30.795976+00:00</updated>
    <content>EUVD-2026-248901</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53010</id>
    <title>fkie_cve-2025-53010</title>
    <updated>2026-10-02T21:39:30.796013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-53010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jhf-gxhr-q4cx</id>
    <title>GHSA-3jhf-gxhr-q4cx — MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph-&gt;getOutput return</title>
    <updated>2026-10-02T21:39:30.796045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: MaterialX</p>
<p>### Summary</p>
<p>When parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files.</p>
<p>### Details</p>
<p>In `src/MaterialXCore/Material.cpp`, in function `getShaderNodes`, the following code fetches the output nodes for a given `nodegraph` input node:</p>
<p>```cpp
// SNIP...
        else if (input-&gt;hasNodeGraphString())
        {
            // Check upstream nodegraph connected to the input.
            // If no explicit output name given then scan all outputs on the nodegraph.
            ElementPtr parent = materialNode-&gt;getParent();
            NodeGraphPtr nodeGraph = parent-&gt;getChildOfType&lt;NodeGraph&gt;(input-&gt;getNodeGraphString());
            if (!nodeGraph)
            {
                continue;
            }
            vector&lt;OutputPtr&gt; outputs;
            if (input-&gt;hasOutputString())
            {
                outputs.push_back(nodeGraph-&gt;getOutput(input-&gt;getOutputString())); // &lt;--- null ptr is returned
            }
            else
            {
                outputs = nodeGraph-&gt;getOutputs();
            }
            for (OutputPtr output : outputs)
            {
                NodePtr upstreamNode = output-&gt;getConnectedNode(); // &lt;--- CRASHES HERE
                if (upstreamNode &amp;&amp; !shaderNodeSet.count(upstreamNode))
                {
                    if (!target.empty() &amp;&amp; !upstreamNode-&gt;getNodeDef(target))
                    {
                        continue;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jhf-gxhr-q4cx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1606</id>
    <title>PYSEC-2026-1606 — MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph-&gt;getOutput return</title>
    <updated>2026-10-02T21:39:30.796090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: materialx</p>
<p>### Summary</p>
<p>When parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files.</p>
<p>### Details</p>
<p>In `src/MaterialXCore/Material.cpp`, in function `getShaderNodes`, the following code fetches the output nodes for a given `nodegraph` input node:</p>
<p>```cpp
// SNIP...
        else if (input-&gt;hasNodeGraphString())
        {
            // Check upstream nodegraph connected to the input.
            // If no explicit output name given then scan all outputs on the nodegraph.
            ElementPtr parent = materialNode-&gt;getParent();
            NodeGraphPtr nodeGraph = parent-&gt;getChildOfType&lt;NodeGraph&gt;(input-&gt;getNodeGraphString());
            if (!nodeGraph)
            {
                continue;
            }
            vector&lt;OutputPtr&gt; outputs;
            if (input-&gt;hasOutputString())
            {
                outputs.push_back(nodeGraph-&gt;getOutput(input-&gt;getOutputString())); // &lt;--- null ptr is returned
            }
            else
            {
                outputs = nodeGraph-&gt;getOutputs();
            }
            for (OutputPtr output : outputs)
            {
                NodePtr upstreamNode = output-&gt;getConnectedNode(); // &lt;--- CRASHES HERE
                if (upstreamNode &amp;&amp; !shaderNodeSet.count(upstreamNode))
                {
                    if (!target.empty() &amp;&amp; !upstreamNode-&gt;getNodeDef(target))
                    {
                        continue;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1606"/>
  </entry>
</feed>
