Junglewise Threat Intelligence

CVE-2022-46294: Open Babel out-of-bounds write in MOPAC input parser

CVE-2022-46294 · Severity: high · CVSS 7.8 · Published 2026-07-01

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel is a widely used software library for converting and processing chemistry data files. A vulnerability in its MOPAC file parser allows a specially crafted file to cause a memory error when opened. This could lead to a program crash or potentially allow an attacker to execute unauthorized code on the system where the file is processed.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the MOPAC input parser of Open Babel. The root cause is the use of a fixed-size array, `translationVectors[]`, which is designed to hold a maximum of three translation vectors. When parsing a malformed MOPAC file containing more than three Tv atoms, the parser continues to write data beyond the array's allocated memory. This memory corruption can be triggered via the `obabel` CLI tool, the `OBConversion` API, or any of the library's language bindings (Python, Java, etc.). Successful exploitation requires a user to open a malicious file and can lead to arbitrary code execution or a denial-of-service. The issue is addressed in version 3.2.0 by adding bounds checking to ensure no more than three vectors are written.

Affected products

  • Open Babel openbabel <= 3.1.1

Timeline

  • 2026-05-09: other: Fix commit authored
  • 2026-05-26: patched: Version 3.2.0 released
  • 2026-07-01: advisory: GitHub Advisory published

References

Related threats