Heap-Based Buffer Overflow in Open Asset Import Library Assimp by Open Asset Import Library
CVE-2026-82591

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82591?

A security issue has been identified in Open Asset Import Library Assimp, affecting versions up to 6.0.2. The problem arises within the MD5Importer::MakeDataUnique function located in the MD5Loader.cpp file. An attacker with local access can manipulate the iNewIndex argument, potentially leading to a heap-based buffer overflow. It is imperative to apply the necessary patch to mitigate this risk and enhance the security of the affected library.

Affected Version(s)

Assimp 6.0.0

Assimp 6.0.1

Assimp 6.0.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Errorgone (VulDB User)
.