Junglewise Threat Intelligence

Open Babel out-of-bounds read in CIF transform3d

Severity: low · CVSS 3.1 · Published 2026-02-19

Technologies: Open Babel.

Executive brief

Open Babel is a widely-used chemistry file format converter shipped by Linux distributions and embedded in many scientific software tools. A flaw in its CIF file parser allows an attacker to craft a malicious chemistry data file that, when opened by the obabel tool or used through the library API, can cause the application to read beyond its internal memory buffer. This could expose sensitive data in memory or crash the application, disrupting chemistry data processing workflows.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in the OpenBabel::transform3d::DescribeAsString function within the CIF file format handler (src/math/transform3d.cpp). A malformed symmetry-operation string in a crafted CIF file causes the parser to read past the end of its internal buffer during string formatting. The attack requires local network access and user interaction (opening the malicious file with obabel or through the OBConversion API). An attacker can trigger memory disclosure or application denial of service. The vulnerability affects all versions up to and including 3.1.1; it was fixed in version 3.2.0 released May 2026.

Affected products

  • Open Babel Open Babel up to and including 3.1.1

Timeline

  • 2026-02-19: disclosed: Publicly disclosed
  • 2026-05-26: patched: Fixed in version 3.2.0

References