Junglewise Threat Intelligence

Open Babel heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

Severity: medium · CVSS 5.3 · Published 2025-09-26

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A vulnerability in its SMILES format parser could allow a local attacker to cause a system crash or potentially access sensitive memory by providing a specially crafted chemical structure file. This could lead to service instability or unauthorized data exposure in applications that rely on this library for processing chemical information.

Technical details

A heap-based buffer overflow vulnerability exists in Open Babel's SMILES parser within the OBSmilesParser::ParseSmiles function located in /src/formats/smilesformat.cpp. The flaw is triggered by an out-of-bounds read on a dynamically allocated vector when processing malformed SMILES (Simplified Molecular Input Line Entry System) strings. An attacker with local access can exploit this by providing a crafted input file to an application using the library, potentially leading to a denial-of-service (crash) or information disclosure. The issue is fixed in version 3.2.0.

Affected products

  • Open Babel openbabel < 3.2.0

Timeline

  • 2025-09-14: disclosed: Initial bug report on GitHub with PoC
  • 2025-09-26: advisory: GitHub Advisory and NVD entry published
  • 2026-06-30: patched: Advisory updated to reflect fix in version 3.2.0

References

Related threats