{"id":"CVE-2025-15647","summary":"CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd","details":"CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data to trigger an out-of-bounds array access that crashes the calling process.","modified":"2026-09-06T08:09:20.822074Z","published":"2026-09-05T11:37:59.945Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15647.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15647.json"},{"type":"PACKAGE","url":"https://github.com/artem-ogre/CDT"},{"type":"ARTICLE","url":"https://github.com/artem-ogre/CDT/blob/1.4.4/CDT/include/CDTUtils.hpp#L175"},{"type":"FIX","url":"https://github.com/artem-ogre/CDT/commit/bf0d11ebfe3da0da72aed91816f665aef1b447cc"},{"type":"REPORT","url":"https://github.com/artem-ogre/CDT/issues/212"},{"type":"ADVISORY","url":"https://github.com/artem-ogre/CDT/releases/tag/1.4.5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15647"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cdt-before-1.4.5-out-of-bounds-read-via-opposedvertexind"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/artem-ogre/cdt","events":[{"introduced":"0"},{"fixed":"2068d015b9db3c92481e869b0c1f669b96a1d70a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.4.5"}],"source":"AFFECTED_FIELD"}}],"versions":["1.4.4","1.4.3","1.4.2","1.4.1","1.4.0","1.3.6","1.3.5","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","1.2.0","1.2","1.1.2","1.1.1","1.1.0","1.0.1","1.0.0","0.9.0"],"database_specific":{"vanir_signatures_modified":"2026-09-06T08:09:20Z","vanir_signatures":[{"source":"https://github.com/artem-ogre/cdt/commit/2068d015b9db3c92481e869b0c1f669b96a1d70a","target":{"file":"CDT/tests/cdt.test.cpp"},"deprecated":false,"digest":{"line_hashes":["253843401789337736866249950690114031637","38007821291801855928126927508795044168","325814626625485553346722033341461022505","145546720321283915722955646076001189712","120942135892600790935361347750135984533","265285209433352185991100072161641824765"],"threshold":0.9},"id":"CVE-2025-15647-086e6c4b","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"length":881,"function_hash":"187527078421929416168465892822096221260"},"id":"CVE-2025-15647-09efc168","signature_type":"Function","signature_version":"v1","source":"https://github.com/artem-ogre/cdt/commit/2068d015b9db3c92481e869b0c1f669b96a1d70a","target":{"function":"isEdgeSplitVertexValid","file":"CDT/include/Triangulation.hpp"}},{"signature_version":"v1","source":"https://github.com/artem-ogre/cdt/commit/2068d015b9db3c92481e869b0c1f669b96a1d70a","target":{"file":"CDT/include/CDTUtils.h"},"deprecated":false,"digest":{"line_hashes":["142420202021066570879622520004080074399","231840131146558323798719270335605424818","317532431642335155540026802283984337650"],"threshold":0.9},"id":"CVE-2025-15647-a6ee4029","signature_type":"Line"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["272834856032517272610121571961418578275","147464765630192657708940566090517777217","8542246207458306185590508860064428923","199673502784664772009758524612373034","118276716199956375514603008374937273007","137542422739906743184364939105261055463","176101671266897218597862551168017049601","140663423794011426807316581249886092845","3905725660658415306392210361167874126"]},"id":"CVE-2025-15647-ab2dd1cb","signature_type":"Line","signature_version":"v1","source":"https://github.com/artem-ogre/cdt/commit/2068d015b9db3c92481e869b0c1f669b96a1d70a","target":{"file":"CDT/include/Triangulation.hpp"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15647.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}