Openbabel: Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
A vulnerability in Open Babel up to version 3.1.1 affects the CDXML file handler component, specifically the OBAtom::GetExplicitValence function. This issue leads to a null pointer dereference, which can be triggered remotely. The advisory is a duplicate and has been withdrawn in favor of another reference. A patch is available and it is recommended to apply it to resolve the issue.
AI Analysis
Technical Summary
The vulnerability in Open Babel (<=3.1.1) involves a null pointer dereference in the OBAtom::GetExplicitValence function within the CDXML file handler (isrc/atom.cpp). This flaw can be triggered remotely, potentially causing a denial of service or application crash. The advisory is a duplicate of GHSA-rxpr-wq63-jr7p and has been withdrawn to maintain external references. A patch identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a addresses the issue. Exploits are publicly available, but no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows remote attackers to cause a null pointer dereference, which may lead to application crashes or denial of service conditions. There is no indication of privilege escalation or data compromise. The severity is assessed as low.
Mitigation Recommendations
A patch is available for this vulnerability (commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a). It is recommended to update Open Babel to version 3.2.0 or later where this issue is resolved. No other mitigations are specified.
Openbabel: Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
Description
A vulnerability in Open Babel up to version 3.1.1 affects the CDXML file handler component, specifically the OBAtom::GetExplicitValence function. This issue leads to a null pointer dereference, which can be triggered remotely. The advisory is a duplicate and has been withdrawn in favor of another reference. A patch is available and it is recommended to apply it to resolve the issue.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Open Babel (<=3.1.1) involves a null pointer dereference in the OBAtom::GetExplicitValence function within the CDXML file handler (isrc/atom.cpp). This flaw can be triggered remotely, potentially causing a denial of service or application crash. The advisory is a duplicate of GHSA-rxpr-wq63-jr7p and has been withdrawn to maintain external references. A patch identified by commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a addresses the issue. Exploits are publicly available, but no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows remote attackers to cause a null pointer dereference, which may lead to application crashes or denial of service conditions. There is no indication of privilege escalation or data compromise. The severity is assessed as low.
Mitigation Recommendations
A patch is available for this vulnerability (commit e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a). It is recommended to update Open Babel to version 3.2.0 or later where this issue is resolved. No other mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fg6r-xgp8-x64r
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- LOW
- Cvss Version
- 4.0
Threat ID: 6a4452e027e9c797198e1040
Added to database: 06/30/2026, 23:36:00 UTC
Last enriched: 06/30/2026, 23:46:17 UTC
Last updated: 07/31/2026, 14:56:50 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.