{"id":"CVE-2026-19968","summary":"Open Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_MDL7 heap-based overflow","details":"A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.","modified":"2026-08-22T09:15:49.007057Z","published":"2026-08-17T00:45:14.688Z","database_specific":{"cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19968.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"17c12da"},{"last_affected":"17c12da"}]}],"cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19968.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19968"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-19968"},{"type":"ADVISORY","url":"https://vuldb.com/submit/873129"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/391145"},{"type":"REPORT","url":"https://github.com/assimp/assimp/issues/6630"},{"type":"REPORT","url":"https://vuldb.com/vuln/391145/cti"},{"type":"FIX","url":"https://github.com/assimp/assimp/commit/ee77bb09a42a49843ac85ef64c14d2328b251df1"},{"type":"FIX","url":"https://github.com/assimp/assimp/pull/6717"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/27425090/poc.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/assimp/assimp","events":[{"introduced":"0"},{"fixed":"ee77bb09a42a49843ac85ef64c14d2328b251df1"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19968.json","vanir_signatures_modified":"2026-08-22T09:15:49Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"202196388722793901961044973007247543352","length":346},"id":"CVE-2026-19968-b8f229d0","signature_type":"Function","signature_version":"v1","source":"https://github.com/assimp/assimp/commit/ee77bb09a42a49843ac85ef64c14d2328b251df1","target":{"file":"code/AssetLib/LWO/LWOLoader.h","function":"LWOImporter::ReadVSizedIntLWO2"}},{"signature_version":"v1","source":"https://github.com/assimp/assimp/commit/ee77bb09a42a49843ac85ef64c14d2328b251df1","target":{"file":"code/AssetLib/LWO/LWOLoader.h"},"deprecated":false,"digest":{"line_hashes":["77171440472505540377557896755629444868","7625515691797164619105776369620194556","70354136064159041416073490227782592689","317214581137535881449677612507319167461","267387026997153857931529273377016611497","70548963861306697612037091711544384319","23530900523560036387739825031117239459","65274315308776297551963963749366137536","151943001445265009615859737790831933026","16500978077527684374249149985493954443","103708077063877253014500131858850971435","304821208644161892629692801651297352170","222008325521717911926671620388751190066","2475160411350359381344389114973539819","13272895742827941864010673580778240578","241052143385281271848629075758522477959","331000839337365724571815160687651557729","228439078923818719090112943470032427422","74387082046443178366377574784278952042","325863489862828762800076405579407644213","94989224821843557218848024086817141339","49783575525568689744929910066421538495","77986545761946537405229450952258036305","211396000077914890137986256458079054265","162897786506477548529509607732487400102","322064036455970532549900314725196445640"],"threshold":0.9},"id":"CVE-2026-19968-f3503156","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}