<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:31:25.194435+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14410</id>
    <title>bdu:2025-14410</title>
    <updated>2026-10-08T21:31:25.335710+00:00</updated>
    <content>bdu:2025-14410</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253577</id>
    <title>EUVD-2026-253577</title>
    <updated>2026-10-08T21:31:25.335750+00:00</updated>
    <content>EUVD-2026-253577</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-10994</id>
    <title>fkie_cve-2025-10994</title>
    <updated>2026-10-08T21:31:25.335765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-10994"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pp85-5j63-xpq3</id>
    <title>GHSA-pp85-5j63-xpq3 — Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule</title>
    <updated>2026-10-08T21:31:25.335796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openbabel</p>
<p>### Summary</p>
<p>A memory-safety vulnerability in Open Babel's GAMESS output parser
caused a use-after-free when reading a crafted input file.</p>
<p>### Details</p>
<p>The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.</p>
<p>### Impact</p>
<p>Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).</p>
<p>### Affected versions</p>
<p>All releases up to and including 3.1.1.</p>
<p>### Patched version</p>
<p>3.2.0 (released 2026-05-26).</p>
<p>### Patch</p>
<p>Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.</p>
<p>A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.</p>
<p>### Credit</p>
<p>Reported via OSS-Fuzz.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pp85-5j63-xpq3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11259-1</id>
    <title>openSUSE-SU-2026:11259-1 — libopenbabel8-3.2.1-1.1 on GA media</title>
    <updated>2026-10-08T21:31:25.335837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenbabel8-3.2.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11259-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2789</id>
    <title>PYSEC-2026-2789 — Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule</title>
    <updated>2026-10-08T21:31:25.335856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openbabel</p>
<p>### Summary</p>
<p>A memory-safety vulnerability in Open Babel's GAMESS output parser
caused a use-after-free when reading a crafted input file.</p>
<p>### Details</p>
<p>The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.</p>
<p>### Impact</p>
<p>Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).</p>
<p>### Affected versions</p>
<p>All releases up to and including 3.1.1.</p>
<p>### Patched version</p>
<p>3.2.0 (released 2026-05-26).</p>
<p>### Patch</p>
<p>Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.</p>
<p>A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.</p>
<p>### Credit</p>
<p>Reported via OSS-Fuzz.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10994</id>
    <title>UBUNTU-CVE-2025-10994</title>
    <updated>2026-10-08T21:31:25.335890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: openbabel, Ubuntu:18.04:LTS: openbabel, Ubuntu:20.04:LTS: openbabel, Ubuntu:22.04:LTS: openbabel, Ubuntu:24.04:LTS: openbabel, Ubuntu:25.10: openbabel, Ubuntu:26.04:LTS: openbabel</p>
<p>A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10994"/>
  </entry>
</feed>
