Junglewise Threat Intelligence

CVE-2022-42885: Open Babel uninitialized pointer dereference in GRO residue parser

CVE-2022-42885 · Severity: high · CVSS 7.8 · Published 2026-07-01

Technologies: openbabel (PyPI), Open Babel. Vendors: PyPI.

Executive brief

Open Babel, a widely used chemistry data conversion library, contains a memory safety flaw in its GRO file format parser. If a user or automated service processes a specially crafted chemistry file, it could lead to a program crash or potentially allow an attacker to execute unauthorized code. This affects researchers and organizations using Open Babel to handle untrusted molecular data files.

Technical details

A memory-safety vulnerability (CWE-824) exists in Open Babel's GRO reader due to improper residue handling. A malformed record in a GRO file causes the parser to access a residue pointer that has not been initialized. Exploitation requires a victim to open a crafted GRO file using the 'obabel' CLI tool, the OBConversion API, or any of the supported language bindings (Python, Java, etc.). While primarily leading to a denial-of-service (crash), some reports suggest it could potentially lead to arbitrary code execution. The issue is fixed in version 3.2.0.

Affected products

  • Open Babel Open Babel <= 3.1.1

Timeline

  • 2026-05-26: patched: Version 3.2.0 released
  • 2026-07-01: advisory: GitHub Advisory published

References

Related threats