Executive brief
Open Babel is a chemistry software library used to convert and manipulate molecular structure files. A flaw in how it parses MOL2 files can cause the application to read memory beyond allocated buffer boundaries, leading to application crashes or potential information disclosure. This affects any system that processes untrusted MOL2 files with Open Babel.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in the OBAtom::SetFormalCharge function within the MOL2 file handler component of Open Babel. The root cause is a buffer overread in the transform3d::DescribeAsString function when processing specially crafted CIF/MMCIF files with malformed Space Group definitions. An attacker can trigger this by providing a malicious MOL2/CIF file to Open Babel, which does not require authentication or special privileges. The crash is reproducible remotely and the exploit has been made public. The vulnerability affects Open Babel versions up to 3.1.1 and is fixed in version 3.2.0.
Affected products
- Open Babel Open Babel up to 3.1.1
Timeline
- 2026-02-19: disclosed
- 2026-02-19: advisory: Advisory published by GitHub advisory database
- 2026: patched: Fixed in version 3.2.0