{"id":"CVE-2026-2653","summary":"admesh normals.c stl_check_normal_vector heap-based overflow","details":"A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.","aliases":["PYSEC-2026-5"],"modified":"2026-08-12T03:51:27.896572696Z","published":"2026-02-18T11:02:07.838Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2653.json","cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"]},"references":[{"type":"WEB","url":"https://github.com/admesh/admesh/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2653.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2653"},{"type":"ADVISORY","url":"https://vuldb.com/?id.346450"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.752596"},{"type":"REPORT","url":"https://github.com/admesh/admesh/issues/65"},{"type":"REPORT","url":"https://github.com/admesh/admesh/issues/65#issuecomment-3804571402"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.346450"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/24878279/id.000035.sig.06.src.000550.time.910126.execs.241742.op.havoc.rep.5.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/admesh/admesh","events":[{"introduced":"ddbb2238caad0ef5068142f274a8c6e474340bdc"},{"last_affected":"70ca24a9b4e6d8aa05e8572e768110dad9b4d47b"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:admesh_project:admesh:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.98.0"},{"last_affected":"0.98.0"},{"introduced":"0.98.1"},{"last_affected":"0.98.1"},{"introduced":"0.98.2"},{"last_affected":"0.98.2"},{"introduced":"0.98.3"},{"last_affected":"0.98.3"},{"introduced":"0.98.4"},{"last_affected":"0.98.4"},{"introduced":"0.98.5"},{"last_affected":"0.98.5"},{"introduced":"0"}]}}],"versions":["0.98.0","0.98.1","0.98.2","0.98.3","0.98.4","0.98.5","v0.98.5","v0.98.4","v0.98.3","v0.98.2","v0.98.1","v0.98.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2653.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}