Executive brief
Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A vulnerability in the software's CACAO file format handler can cause the application to crash when processing specifically crafted chemical files. This could lead to a denial-of-service, impacting the availability of research tools or automated chemical processing pipelines.
Technical details
A NULL pointer dereference exists in Open Babel versions prior to 3.2.0 within the CacaoFormat::SetHilderbrandt function in /src/formats/cacaoformat.cpp. The vulnerability is triggered when the function assumes all OBAtom pointers in its internal coordinate list are valid without proper verification. An attacker with local access can provide a crafted input file to trigger a crash (segmentation fault) via a READ memory access at a zero-page address. This issue was identified via fuzzing and is addressed in version 3.2.0.
Affected products
- Open Babel openbabel < 3.2.0
Timeline
- 2025-09-14: disclosed: Issue reported on GitHub with PoC
- 2025-09-26: advisory: Initial GHSA and NVD publication
- 2026-07-01: patched: Version 3.2.0 released and advisory updated