Buffer Overflow Vulnerability in Open Asset Import Library Assimp's 3DGS MDL7 Model Output Mesh Generator
CVE-2026-19969
Key Information:
- Vendor
Open Asset Import Library
- Status
- Vendor
- CVE Published:
- 17 August 2026
Badges
What is CVE-2026-19969?
A security vulnerability identified in the Open Asset Import Library Assimp version 17c12da affects the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 within the MDLLoader.cpp file. This vulnerability allows for a buffer overflow due to improper handling of input data, which could potentially be exploited remotely. Although the issue was reported to the project maintainers ahead of time, there has been no acknowledgment or response to address the flaw. Public disclosure of the exploit signifies an immediate need for users to be vigilant and consider necessary security measures.
Affected Version(s)
Assimp 17c12da
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
