Executive brief
Open Babel, a widely used library for processing chemistry file formats, contains a memory-safety vulnerability in its decompression component. An attacker could provide a specially crafted gzip-compressed chemistry file that, when opened by a user or processed by a service, could lead to a system crash or unauthorized code execution. This affects researchers and organizations using the library's command-line tools or its various programming language interfaces (such as Python, Java, and C#).
Technical details
An out-of-bounds write vulnerability exists in Open Babel's bundled zipstream implementation, specifically within the 'basic_unzip_streambuf::underflow' function in 'src/zipstreamimpl.h'. The flaw is caused by the use of 'memcpy' on overlapping memory regions during the decompression buffer refill path, which constitutes undefined behavior and results in memory corruption. An attacker can exploit this by providing a malicious gzip-compressed chemistry file to be parsed via the 'obabel' CLI, 'OBConversion' API, or any supported language bindings. The vulnerability was identified via OSS-Fuzz and is addressed in version 3.2.0.
Affected products
- Open Babel Open Babel <= 3.1.1
Timeline
- 2025-09-14: other: Initial bug report submitted
- 2026-05-26: patched: Version 3.2.0 released
- 2026-06-30: advisory: GitHub Advisory published
References
- https://github.com/openbabel/openbabel/security/advisories/GHSA-8j3x-m868-cpw8
- https://github.com/openbabel/openbabel/issues/2832
- https://github.com/openbabel/openbabel/issues/2913
- https://github.com/openbabel/openbabel/commit/d4621d417c167b50cc8ce7aa3a02557e5b2b81c5
- https://github.com/user-attachments/files/22318572/poc.zip