<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 19:35:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14410</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14410</link>
      <description>bdu:2025-14410</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14410</guid>
    </item>
    <item>
      <title>EUVD-2026-253577</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253577</link>
      <description>EUVD-2026-253577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253577</guid>
    </item>
    <item>
      <title>fkie_cve-2025-10994</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-10994</link>
      <description>&lt;p&gt;A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-10994</guid>
    </item>
    <item>
      <title>GHSA-pp85-5j63-xpq3 — Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pp85-5j63-xpq3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openbabel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A memory-safety vulnerability in Open Babel&amp;#39;s GAMESS output parser
caused a use-after-free when reading a crafted input file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All releases up to and including 3.1.1.&lt;/p&gt;
&lt;p&gt;### Patched version&lt;/p&gt;
&lt;p&gt;3.2.0 (released 2026-05-26).&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.&lt;/p&gt;
&lt;p&gt;A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported via OSS-Fuzz.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openbabel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A memory-safety vulnerability in Open Babel&amp;#39;s GAMESS output parser
caused a use-after-free when reading a crafted input file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All releases up to and including 3.1.1.&lt;/p&gt;
&lt;p&gt;### Patched version&lt;/p&gt;
&lt;p&gt;3.2.0 (released 2026-05-26).&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.&lt;/p&gt;
&lt;p&gt;A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported via OSS-Fuzz.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pp85-5j63-xpq3</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11259-1 — libopenbabel8-3.2.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11259-1</link>
      <description>&lt;p&gt;libopenbabel8-3.2.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenbabel8-3.2.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11259-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2789 — Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openbabel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A memory-safety vulnerability in Open Babel&amp;#39;s GAMESS output parser
caused a use-after-free when reading a crafted input file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All releases up to and including 3.1.1.&lt;/p&gt;
&lt;p&gt;### Patched version&lt;/p&gt;
&lt;p&gt;3.2.0 (released 2026-05-26).&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.&lt;/p&gt;
&lt;p&gt;A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported via OSS-Fuzz.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openbabel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A memory-safety vulnerability in Open Babel&amp;#39;s GAMESS output parser
caused a use-after-free when reading a crafted input file.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All releases up to and including 3.1.1.&lt;/p&gt;
&lt;p&gt;### Patched version&lt;/p&gt;
&lt;p&gt;3.2.0 (released 2026-05-26).&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;Fix commit: https://github.com/openbabel/openbabel/commit/95033d27
Originally reported as #2834; fixes consolidated in #2913.&lt;/p&gt;
&lt;p&gt;A minimized reproducer for this CVE is checked in under
`test/files/fuzz_regress/` and is exercised on every CI build under
ASAN+UBSAN by the `fuzzregresstest` harness.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported via OSS-Fuzz.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2789</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-10994</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10994</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openbabel, Ubuntu:18.04:LTS: openbabel, Ubuntu:20.04:LTS: openbabel, Ubuntu:22.04:LTS: openbabel, Ubuntu:24.04:LTS: openbabel, Ubuntu:25.10: openbabel, Ubuntu:26.04:LTS: openbabel&lt;/p&gt;
&lt;p&gt;A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openbabel, Ubuntu:18.04:LTS: openbabel, Ubuntu:20.04:LTS: openbabel, Ubuntu:22.04:LTS: openbabel, Ubuntu:24.04:LTS: openbabel, Ubuntu:25.10: openbabel, Ubuntu:26.04:LTS: openbabel&lt;/p&gt;
&lt;p&gt;A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10994</guid>
    </item>
  </channel>
</rss>
