CVE-2026-2705
published 2026-02-19CVE-2026-2705: A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of…
PriorityP345high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.70%
49.1th percentile
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openbabel | — | — |
| debian | openbabel | >= 0 < 3.2.0 | 3.2.0 |
| openbabel | open_babel | <= 3.1.1 | — |
| openbabel | open_babel | — | — |
| openbabel | open_babel | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Open Babel up to 3.1.1 MOL2 File include/openbabel/atom.h OBAtom::SetFormalCharge out-of-bounds (Issue 2848 / EUVD-2026-7561)
vuldb·2026-06-30·CVSS 8.1
CVE-2026-2705 [HIGH] Open Babel up to 3.1.1 MOL2 File include/openbabel/atom.h OBAtom::SetFormalCharge out-of-bounds (Issue 2848 / EUVD-2026-7561)
A vulnerability labeled as critical has been found in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-2705. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.
The project was informed of the problem early through an issue report but has not responded yet.
GHSA
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
ghsa·2026-06-30
CVE-2026-2705 [LOW] CWE-119 Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
### Summary
A memory-safety vulnerability in Open Babel's MOL2 file format parser
caused a NULL pointer dereference when reading a crafted input file.
### Details
The flaw was in `OBAtom::SetFormalCharge` as called from the MOL2
parser. A malformed atom record caused the parser to call the method
on a NULL atom pointer.
### Impact
Open Babel is a C++ library and CLI used to read and write chemistry
file formats; it is shipped by Linux distributions and embedded in
services that may parse untrusted input. Triggering this vulnerability
requires the victim to open a malicious MOL2 file with the `obabel`
tool, the `OBConversion` API, or any of the language bindings (Python,
Ruby, Java, R, Perl, C#, PHP).
### Affecte
GHSA
GHSA-3f56-w4g2-mx64: A vulnerability was detected in Open Babel up to 3
ghsa_unreviewed·2026-02-19
CVE-2026-2705 [MEDIUM] CWE-119 GHSA-3f56-w4g2-mx64: A vulnerability was detected in Open Babel up to 3
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
OSV
CVE-2026-2705: A vulnerability was detected in Open Babel up to 3
osv·2026-02-19·CVSS 5.3
CVE-2026-2705 [MEDIUM] CVE-2026-2705: A vulnerability was detected in Open Babel up to 3
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
Debian
CVE-2026-2705: openbabel - A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is ...
vendor_debian·2026·CVSS 5.3
CVE-2026-2705 [MEDIUM] CVE-2026-2705: openbabel - A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is ...
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08ahttps://github.com/oneafter/0128/blob/main/ob2/repro.mol2https://github.com/openbabel/openbabel/issues/2848https://github.com/openbabel/openbabel/pull/2862https://vuldb.com/?ctiid.346651https://vuldb.com/?id.346651https://vuldb.com/?submit.754379
2026-02-19
Published