<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:54:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-53010 — MaterialX's unchecked nodeGraph-&gt;getOutput return is vulnerable to NULL Pointer Dereference</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-53010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AcademySoftwareFoundation MaterialX&lt;/p&gt;
&lt;p&gt;MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AcademySoftwareFoundation MaterialX&lt;/p&gt;
&lt;p&gt;MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-53010</guid>
    </item>
    <item>
      <title>GHSA-3jhf-gxhr-q4cx — MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph-&gt;getOutput return</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3jhf-gxhr-q4cx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: MaterialX&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `src/MaterialXCore/Material.cpp`, in function `getShaderNodes`, the following code fetches the output nodes for a given `nodegraph` input node:&lt;/p&gt;
&lt;p&gt;```cpp
// SNIP...
        else if (input-&amp;gt;hasNodeGraphString())
        {
            // Check upstream nodegraph connected to the input.
            // If no explicit output name given then scan all outputs on the nodegraph.
            ElementPtr parent = materialNode-&amp;gt;getParent();
            NodeGraphPtr nodeGraph = parent-&amp;gt;getChildOfType&amp;lt;NodeGraph&amp;gt;(input-&amp;gt;getNodeGraphString());
            if (!nodeGraph)
            {
                continue;
            }
            vector&amp;lt;OutputPtr&amp;gt; outputs;
            if (input-&amp;gt;hasOutputString())
            {
                outputs.push_back(nodeGraph-&amp;gt;getOutput(input-&amp;gt;getOutputString())); // &amp;lt;--- null ptr is returned
            }
            else
            {
                outputs = nodeGraph-&amp;gt;getOutputs();
            }
            for (OutputPtr output : outputs)
            {
                NodePtr upstreamNode = output-&amp;gt;getConnectedNode(); // &amp;lt;--- CRASHES HERE
                if (upstreamNode &amp;amp;&amp;amp; !shaderNodeSet.count(upstreamNode))
                {
                    if (!target.empty() &amp;amp;&amp;amp; !upstreamNode-&amp;gt;getNodeDef(target))
                    {
                        continue;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: MaterialX&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `src/MaterialXCore/Material.cpp`, in function `getShaderNodes`, the following code fetches the output nodes for a given `nodegraph` input node:&lt;/p&gt;
&lt;p&gt;```cpp
// SNIP...
        else if (input-&amp;gt;hasNodeGraphString())
        {
            // Check upstream nodegraph connected to the input.
            // If no explicit output name given then scan all outputs on the nodegraph.
            ElementPtr parent = materialNode-&amp;gt;getParent();
            NodeGraphPtr nodeGraph = parent-&amp;gt;getChildOfType&amp;lt;NodeGraph&amp;gt;(input-&amp;gt;getNodeGraphString());
            if (!nodeGraph)
            {
                continue;
            }
            vector&amp;lt;OutputPtr&amp;gt; outputs;
            if (input-&amp;gt;hasOutputString())
            {
                outputs.push_back(nodeGraph-&amp;gt;getOutput(input-&amp;gt;getOutputString())); // &amp;lt;--- null ptr is returned
            }
            else
            {
                outputs = nodeGraph-&amp;gt;getOutputs();
            }
            for (OutputPtr output : outputs)
            {
                NodePtr upstreamNode = output-&amp;gt;getConnectedNode(); // &amp;lt;--- CRASHES HERE
                if (upstreamNode &amp;amp;&amp;amp; !shaderNodeSet.count(upstreamNode))
                {
                    if (!target.empty() &amp;amp;&amp;amp; !upstreamNode-&amp;gt;getNodeDef(target))
                    {
                        continue;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3jhf-gxhr-q4cx</guid>
    </item>
  </channel>
</rss>
