Executive brief
Open Babel is a widely used chemistry software library and command-line tool for converting between different chemical file formats. A vulnerability in its SMILES (Simplified Molecular Input Line Entry System) parser allows a specially crafted chemical string to cause a memory crash. If an application or service uses Open Babel to process untrusted chemical data, an attacker could potentially execute malicious code or cause the system to crash, leading to data theft or service disruption.
Technical details
A heap buffer overflow exists in the OBSmilesParser::ParseSmiles function within src/formats/smilesformat.cpp of Open Babel. The vulnerability is triggered when the parser handles malformed SMILES input strings, leading to an out-of-bounds write on a heap-allocated buffer. An attacker can exploit this by providing a malicious SMILES string to the obabel CLI tool, the OBConversion API, or any of the supported language bindings (such as Python, Java, or C#). This can result in arbitrary code execution or a denial-of-service condition. The issue was identified via OSS-Fuzz and is resolved in version 3.2.0.
Affected products
- Open Babel openbabel <= 3.1.1
Timeline
- 2025-09-14: disclosed: Initial bug report on GitHub
- 2025-09-25: other: CVE assigned and published to VulDB
- 2026-05-26: patched: Version 3.2.0 released
- 2026-06-30: advisory: GitHub Advisory published