Junglewise Threat Intelligence

CVE-2026-82591: Open Asset Import Library Assimp heap buffer overflow in MD5Importer

CVE-2026-82591 · Severity: medium · CVSS 5.3 · Published 2026-08-30

Technologies: Assimp Open Asset Import Library. Vendors: Assimp.

Executive brief

Assimp is a widely-used library for importing and processing 3D model files across games and design software. A heap buffer overflow in the MD5 file parser allows a local attacker to crash the application or potentially execute code by providing a malicious MD5 model file, impacting any application using the vulnerable library version.

Technical details

A heap-based buffer overflow exists in the MD5Importer::MakeDataUnique function in code/AssetLib/MD5/MD5Loader.cpp, triggered by improper handling of the iNewIndex argument during memory manipulation. The vulnerability requires local access and a specially crafted MD5 model file to trigger. An attacker can cause a heap buffer overflow write, leading to application crash (denial of service) or potential code execution depending on heap layout. A patch has been identified (commit bf9dabb617c46e5133dac65cca6bff177917afcb) and is available in the upstream repository.

Affected products

  • Assimp Open Asset Import Library up to 6.0.2

Timeline

  • 2026-08-30: disclosed
  • 2026-08-04: patched: Fix merged in upstream repository

References

Related threats