CVE-2025-10994
published 2025-09-26CVE-2025-10994: A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.5th percentile
A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openbabel | — | — |
| debian | openbabel | >= 0 < 3.2.0 | 3.2.0 |
| openbabel | open_babel | <= 3.1.1 | — |
| openbabel | open_babel | — | — |
| openbabel | open_babel | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.8MEDIUM
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Open Babel up to 3.1.1 gamessformat.cpp ReadMolecule use after free (Issue 2834 / EUVD-2025-31200)
vuldb·2026-06-30·CVSS 7.8
CVE-2025-10994 [HIGH] Open Babel up to 3.1.1 gamessformat.cpp ReadMolecule use after free (Issue 2834 / EUVD-2025-31200)
A vulnerability, which was classified as critical, has been found in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free.
This vulnerability is handled as CVE-2025-10994. It is possible to launch the attack on the local host. Additionally, an exploit exists.
GHSA
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
ghsa·2026-06-30
CVE-2025-10994 [LOW] CWE-119 Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
### Summary
A memory-safety vulnerability in Open Babel's GAMESS output parser
caused a use-after-free when reading a crafted input file.
### Details
The flaw was in `GAMESSOutputFormat::ReadMolecule`. A malformed input
caused the parser to dereference a stale pointer after the underlying
object had been freed.
### Impact
Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious GAMESS output file with the
`obabel` tool, the `OBConversion` API, or any of the language
bindings (Python, Ruby, Java, R, Perl, C#, PHP).
### Affect
OSV
CVE-2025-10994: A weakness has been identified in Open Babel up to 3
osv·2025-09-26·CVSS 4.8
CVE-2025-10994 [MEDIUM] CVE-2025-10994: A weakness has been identified in Open Babel up to 3
A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.
GHSA
GHSA-5fgf-q57f-wwqf: A weakness has been identified in Open Babel up to 3
ghsa_unreviewed·2025-09-26
CVE-2025-10994 [MEDIUM] CWE-119 GHSA-5fgf-q57f-wwqf: A weakness has been identified in Open Babel up to 3
A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.
Debian
CVE-2025-10994: openbabel - A weakness has been identified in Open Babel up to 3.1.1. This affects the funct...
vendor_debian·2025·CVSS 4.8
CVE-2025-10994 [MEDIUM] CVE-2025-10994: openbabel - A weakness has been identified in Open Babel up to 3.1.1. This affects the funct...
A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
2025-09-26
Published