Junglewise Threat Intelligence

CVE-2022-46290: Open Babel heap buffer overflow in ORCA nAtoms parser

CVE-2022-46290 · Severity: high · CVSS 7.8 · Published 2026-07-01

Technologies: openbabel (PyPI), Open Babel. Vendors: PyPI.

Executive brief

Open Babel, a widely used library for processing chemistry file formats, contains a memory safety flaw in its ORCA file parser. An attacker could provide a specially crafted chemistry file that, when opened by a user or processed by a service using this library, could lead to unauthorized code execution or system crashes. This affects various applications and web services that rely on Open Babel to convert or view molecular data.

Technical details

An out-of-bounds write vulnerability (CWE-787/CWE-122) exists in Open Babel's ORCA format parser within the 'nAtoms' functionality. The vulnerability occurs in 'formats/orcaformat.cpp' where the parser reads the number of atoms from a file and subsequently fills a coordinate buffer without verifying that the input index remains within the allocated bounds of the 'nAtoms' variable. An attacker can trigger this by providing a malformed ORCA file with a mismatched atom count and coordinate list. The exploit requires local user interaction (opening a file) or a service that processes untrusted ORCA files. The issue is patched in version 3.2.0.

Affected products

  • Open Babel Open Babel <= 3.1.1

Timeline

  • 2023-07-21: disclosed: Initial report by Cisco Talos
  • 2026-05-26: patched: Version 3.2.0 released
  • 2026-07-01: advisory: GitHub Advisory published

References

Related threats