Junglewise Threat Intelligence

Open Babel NULL pointer dereference in CacaoFormat::SetHilderbrandt

Severity: low · CVSS 3.3 · Published 2025-09-26

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A vulnerability in the software's CACAO file format handler can cause the application to crash when processing specifically crafted chemical files. This could lead to a denial-of-service, impacting the availability of research tools or automated chemical processing pipelines.

Technical details

A NULL pointer dereference exists in Open Babel versions prior to 3.2.0 within the CacaoFormat::SetHilderbrandt function in /src/formats/cacaoformat.cpp. The vulnerability is triggered when the function assumes all OBAtom pointers in its internal coordinate list are valid without proper verification. An attacker with local access can provide a crafted input file to trigger a crash (segmentation fault) via a READ memory access at a zero-page address. This issue was identified via fuzzing and is addressed in version 3.2.0.

Affected products

  • Open Babel openbabel < 3.2.0

Timeline

  • 2025-09-14: disclosed: Issue reported on GitHub with PoC
  • 2025-09-26: advisory: Initial GHSA and NVD publication
  • 2026-07-01: patched: Version 3.2.0 released and advisory updated

References

Related threats