Description
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Timeline
| 2026-02-18: | Advisory disclosed |
| 2026-02-18: | VulDB entry created |
| 2026-02-21: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.346651 (VDB-346651 | Open Babel MOL2 File atom.h SetFormalCharge out-of-bounds)
vuldb.com/?ctiid.346651 (VDB-346651 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.754379 (Submit #754379 | openbabel master-branch NULL Pointer Dereference)
github.com/openbabel/openbabel/issues/2848
github.com/oneafter/0128/blob/main/ob2/repro.mol2