CVE-2026-19970

A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The manipulation of the argument bones_num results in heap-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 02:16

Updated : 2026-08-20 12:48


NVD link : CVE-2026-19970

Mitre link : CVE-2026-19970

CVE.ORG link : CVE-2026-19970


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow