VDB
CVE-2026-2705
CVE-2026-2705
PUBLISHED
CVSS 4.300000190734863 MEDIUM
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
EPSS 0.72% · 51.5th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS Score
0.72%
51.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openbabel | open_babel | 0, 0 |
| n/a | Open Babel | 3.1.0, 3.1.1, 3.1.0 |
Timeline
- Feb 19, 2026 EPSS Score
- Feb 19, 2026 CVE Published
- Feb 21, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
- Mar 3, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 6, 2026 EPSS Score
- Mar 8, 2026 EPSS Score
- Mar 10, 2026 EPSS Score
References
- https://github.com/openbabel/openbabel/issues/2848 discussion
- VDB-346651 | Open Babel MOL2 File atom.h SetFormalCharge out-of-bounds vdb
- VDB-346651 | CTI Indicators (IOB, IOC, IOA) url
- Submit #754379 | openbabel master-branch NULL Pointer Dereference third-party-advisory
- https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a fix
- https://github.com/oneafter/0128/blob/main/ob2/repro.mol2 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-2705 advisory
- https://github.com/openbabel/openbabel/pull/2862 fix