Buffer Overflow Vulnerability in Open Asset Import Library Assimp
CVE-2026-19999
Key Information:
- Status
- Vendor
- CVE Published:
- 17 August 2026
Badges
What is CVE-2026-19999?
A security vulnerability in Open Asset Import Library Assimp's Bone Transformation Key Parser allows for buffer overflow due to improper handling of the transmatrix_count/pcBoneTransforms argument in the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7. This flaw can be exploited remotely, posing a significant risk. The vulnerability has been disclosed publicly, prompting the recommendation to apply patch 50d767984e78d51b53e2020fdf0967fd624bc377 to mitigate the risk.
Affected Version(s)
Assimp 17c12da
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
