{"id":"CVE-2026-3408","summary":"Open Babel CDXML File atom.cpp GetExplicitValence null pointer dereference","details":"A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is best practice to apply a patch to resolve this issue.","aliases":["GHSA-rxpr-wq63-jr7p","PYSEC-2026-2791"],"modified":"2026-08-12T16:25:03.410111Z","published":"2026-03-02T03:32:10.760Z","related":["openSUSE-SU-2026:11096-1","openSUSE-SU-2026:21190-1"],"database_specific":{"cwe_ids":["CWE-404","CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3408.json","cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3408.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3408"},{"type":"ADVISORY","url":"https://vuldb.com/?id.348303"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.763756"},{"type":"REPORT","url":"https://github.com/openbabel/openbabel/issues/2848"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.348303"},{"type":"FIX","url":"https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a"},{"type":"FIX","url":"https://github.com/openbabel/openbabel/pull/2862"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0128/blob/main/ob3/repro.cdxml"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vedantmadane/openbabel","events":[{"introduced":"0"},{"fixed":"e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a"}],"database_specific":{"cpe":"cpe:2.3:a:openbabel:open_babel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.1.0","3.1.1","openbabel-3-1-0","openbabel-3-1-1","openbabel-3-0-0","openbabel-3-0-0a2","openbabel-3-0-0a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3408.json","vanir_signatures_modified":"2026-08-12T16:25:03Z","vanir_signatures":[{"digest":{"function_hash":"30010962304116138080607436319469699538","length":8741},"id":"CVE-2026-3408-01bc6dd8","signature_type":"Function","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/mol2format.cpp","function":"MOL2Format::ReadMolecule"},"deprecated":false},{"id":"CVE-2026-3408-0f76489d","signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/xml/cdxmlformat.cpp"},"deprecated":false,"digest":{"line_hashes":["217684272962877016414138833642465327871","281597259995795846860484565484922236444","67944802873645976870685274386029446693","284286721701357702013437237273380090033","242538309816058351042879703787182903972"],"threshold":0.9}},{"id":"CVE-2026-3408-33bca003","signature_type":"Function","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/math/transform3d.cpp","function":"transform3d::DescribeAsString"},"deprecated":false,"digest":{"length":1251,"function_hash":"119405193706058877749533351361322555021"}},{"id":"CVE-2026-3408-a7c7b4f1","signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/formats/mol2format.cpp"},"deprecated":false,"digest":{"line_hashes":["74714072063425806463116978712476486227","26720173946644870887389989496423085704","17720890902694951893861370958398576869","241071117686927028701713811667404671016","310400835440742988261621149033241726729","223347280846511975360235714746911352592","113071542473268934638868109943538653392"],"threshold":0.9}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"file":"src/math/transform3d.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["126791517391950924350933049496851609362","273447677231502680745093624288136141499","122020157048298215120106090724374946668","106789864566273743879341108317849902974","40275149034654090481755797826856792854"]},"id":"CVE-2026-3408-b63644bb"},{"deprecated":false,"digest":{"function_hash":"76514931888117891657624299142639965215","length":650},"id":"CVE-2026-3408-f94e2ea9","signature_type":"Function","signature_version":"v1","source":"https://github.com/vedantmadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a","target":{"function":"ChemDrawXMLFormat::EndElement","file":"src/formats/xml/cdxmlformat.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}