CVE-2026-10198

Source
https://cve.org/CVERecord?id=CVE-2026-10198
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10198.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10198
Downstream
Published
2026-05-31T22:15:12.239Z
Modified
2026-07-24T03:57:10.394903819Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
Details

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

Database specific
{
    "cwe_ids": [
        "CWE-404",
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10198.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/assimp/assimp

Affected ranges

Type
GIT
Repo
https://github.com/assimp/assimp
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "last_affected": "6.0.0"
        },
        {
            "introduced": "6.0.1"
        },
        {
            "last_affected": "6.0.1"
        },
        {
            "introduced": "6.0.2"
        },
        {
            "last_affected": "6.0.2"
        },
        {
            "introduced": "6.0.3"
        },
        {
            "last_affected": "6.0.3"
        },
        {
            "introduced": "6.0.4"
        },
        {
            "last_affected": "6.0.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10198.json"