Executive brief
Open CASCADE Technology (OCCT) is a software development platform used for 3D computer-aided design (CAD) and modeling. A vulnerability in its OBJ file parser allows an attacker to crash applications or potentially access sensitive memory by tricking a user into opening a specially crafted 3D model file. This could lead to service disruptions or the exposure of internal system information.
Technical details
A heap-based out-of-bounds read exists in RWObj_Reader::read within the OBJ file parser of Open CASCADE Technology (OCCT). The vulnerability is caused by insufficient validation of the buffer length returned by Standard_ReadLineBuffer::ReadLine(). Specifically, when processing a minimal OBJ line, the function may return a 1-byte buffer; RWObj_Reader::read() subsequently calls pushIndices(aLine + 2) without verifying that the buffer contains enough data for the pointer arithmetic. An attacker can exploit this by persuading a user to open a malicious OBJ file, leading to a 1-byte read past the end of the heap allocation. This can result in a denial of service (application crash) or the leakage of sensitive information from the heap.
Affected products
- Open CASCADE SAS Open CASCADE Technology (OCCT) <= 7.8.1, 8.0.0_rc5, and master through commit c540f316
Timeline
- 2026-04-30: disclosed: Vulnerability reported by Innora Security Research
- 2026-05-01: advisory: NVD published CVE-2026-42477