CVE-2026-3408: NULL Pointer Dereference in Open Babel
A medium severity vulnerability (CVE-2026-3408) exists in Open Babel versions 3.1.0 and 3.1.1. It involves a NULL pointer dereference in the OBAtom::GetExplicitValence function within the CDXML File Handler component. This flaw can be triggered remotely and has a publicly available exploit. A patch identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a is available to address the issue.
AI Analysis
Technical Summary
CVE-2026-3408 is a NULL pointer dereference vulnerability in Open Babel's OBAtom::GetExplicitValence function located in the isrc/atom.cpp file of the CDXML File Handler component. The vulnerability affects Open Babel versions 3.1.0 and 3.1.1. Remote attackers can exploit this flaw, potentially causing a denial of service or application crash. A patch has been released (commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a) to fix the issue. The CVSS 4.0 base score is 5.3, indicating medium severity.
Potential Impact
Successful exploitation of this vulnerability can lead to a NULL pointer dereference, causing the Open Babel application to crash or become unstable. This may result in denial of service conditions. There is no indication of privilege escalation or data confidentiality/integrity impact in the provided data.
Mitigation Recommendations
A patch is available to remediate this vulnerability, identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is recommended to apply this patch to Open Babel versions 3.1.0 and 3.1.1 to resolve the issue. No vendor advisory content was provided, so verify with the official Open Babel sources for the patch details and application instructions.
CVE-2026-3408: NULL Pointer Dereference in Open Babel
Description
A medium severity vulnerability (CVE-2026-3408) exists in Open Babel versions 3.1.0 and 3.1.1. It involves a NULL pointer dereference in the OBAtom::GetExplicitValence function within the CDXML File Handler component. This flaw can be triggered remotely and has a publicly available exploit. A patch identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a is available to address the issue.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/openbabel/openbabelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-3408 is a NULL pointer dereference vulnerability in Open Babel's OBAtom::GetExplicitValence function located in the isrc/atom.cpp file of the CDXML File Handler component. The vulnerability affects Open Babel versions 3.1.0 and 3.1.1. Remote attackers can exploit this flaw, potentially causing a denial of service or application crash. A patch has been released (commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a) to fix the issue. The CVSS 4.0 base score is 5.3, indicating medium severity.
Potential Impact
Successful exploitation of this vulnerability can lead to a NULL pointer dereference, causing the Open Babel application to crash or become unstable. This may result in denial of service conditions. There is no indication of privilege escalation or data confidentiality/integrity impact in the provided data.
Mitigation Recommendations
A patch is available to remediate this vulnerability, identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is recommended to apply this patch to Open Babel versions 3.1.0 and 3.1.1 to resolve the issue. No vendor advisory content was provided, so verify with the official Open Babel sources for the patch details and application instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-03-01T07:11:14.065Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69a50ddf32ffcdb8a25b4131
Added to database: 03/02/2026, 04:11:11 UTC
Last enriched: 06/30/2026, 23:46:11 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 199
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.