{"id":"CVE-2026-2704","summary":"Open Babel CIF File transform3d.cpp DescribeAsString out-of-bounds","details":"A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.0 is sufficient to fix this issue. The identifier of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is suggested to install a patch to address this issue.","aliases":["GHSA-6xw4-2g22-26h8","PYSEC-2026-2774"],"modified":"2026-08-12T16:24:55.255033Z","published":"2026-02-19T04:32:07.297Z","related":["openSUSE-SU-2026:11096-1","openSUSE-SU-2026:21190-1"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2704.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2704.json"},{"type":"ADVISORY","url":"https://github.com/openbabel/openbabel/security/advisories/GHSA-6xw4-2g22-26h8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2704"},{"type":"ADVISORY","url":"https://vuldb.com/submit/754378"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/346650"},{"type":"REPORT","url":"https://github.com/openbabel/openbabel/issues/2848"},{"type":"REPORT","url":"https://vuldb.com/vuln/346650/cti"},{"type":"FIX","url":"https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a"},{"type":"FIX","url":"https://github.com/openbabel/openbabel/pull/2862"},{"type":"FIX","url":"https://github.com/openbabel/openbabel/releases/tag/openbabel-3-2-0"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0128/blob/main/ob1/repro.cif"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openbabel/openbabel","events":[{"introduced":"0"},{"fixed":"5046ed24e1c33180537715e0204f3111125eb595"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/vedantmadane/openbabel","events":[{"introduced":"0"},{"fixed":"e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a"}],"database_specific":{"cpe":"cpe:2.3:a:openbabel:open_babel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.1.0","3.1.1","openbabel-3-1-0","openbabel-3-1-1","openbabel-3-0-0","openbabel-3-0-0a2","openbabel-3-0-0a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2704.json","vanir_signatures_modified":"2026-08-12T16:24:55Z","vanir_signatures":[{"id":"CVE-2026-2704-01bc6dd8","signature_type":"Function","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/mol2format.cpp","function":"MOL2Format::ReadMolecule"},"deprecated":false,"digest":{"function_hash":"30010962304116138080607436319469699538","length":8741}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/xml/cdxmlformat.cpp"},"deprecated":false,"digest":{"line_hashes":["217684272962877016414138833642465327871","281597259995795846860484565484922236444","67944802873645976870685274386029446693","284286721701357702013437237273380090033","242538309816058351042879703787182903972"],"threshold":0.9},"id":"CVE-2026-2704-0f76489d"},{"source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/math/transform3d.cpp","function":"transform3d::DescribeAsString"},"deprecated":false,"digest":{"function_hash":"119405193706058877749533351361322555021","length":1251},"id":"CVE-2026-2704-33bca003","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/mol2format.cpp"},"deprecated":false,"digest":{"line_hashes":["74714072063425806463116978712476486227","26720173946644870887389989496423085704","17720890902694951893861370958398576869","241071117686927028701713811667404671016","310400835440742988261621149033241726729","223347280846511975360235714746911352592","113071542473268934638868109943538653392"],"threshold":0.9},"id":"CVE-2026-2704-a7c7b4f1"},{"digest":{"line_hashes":["126791517391950924350933049496851609362","273447677231502680745093624288136141499","122020157048298215120106090724374946668","106789864566273743879341108317849902974","40275149034654090481755797826856792854"],"threshold":0.9},"id":"CVE-2026-2704-b63644bb","signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/math/transform3d.cpp"},"deprecated":false},{"source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/xml/cdxmlformat.cpp","function":"ChemDrawXMLFormat::EndElement"},"deprecated":false,"digest":{"function_hash":"76514931888117891657624299142639965215","length":650},"id":"CVE-2026-2704-f94e2ea9","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}