CVE-2026-19968

Source
https://cve.org/CVERecord?id=CVE-2026-19968
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19968.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19968
Downstream
Published
2026-08-17T00:45:14Z
Modified
2026-08-22T09:15:49Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Open Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_MDL7 heap-based overflow
Details

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19968.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "17c12da"
                },
                {
                    "last_affected": "17c12da"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/assimp/assimp

Affected ranges

Type
GIT
Repo
https://github.com/assimp/assimp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19968.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "202196388722793901961044973007247543352",
            "length": 346
        },
        "id": "CVE-2026-19968-b8f229d0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/assimp/assimp/commit/ee77bb09a42a49843ac85ef64c14d2328b251df1",
        "target": {
            "file": "code/AssetLib/LWO/LWOLoader.h",
            "function": "LWOImporter::ReadVSizedIntLWO2"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "77171440472505540377557896755629444868",
                "7625515691797164619105776369620194556",
                "70354136064159041416073490227782592689",
                "317214581137535881449677612507319167461",
                "267387026997153857931529273377016611497",
                "70548963861306697612037091711544384319",
                "23530900523560036387739825031117239459",
                "65274315308776297551963963749366137536",
                "151943001445265009615859737790831933026",
                "16500978077527684374249149985493954443",
                "103708077063877253014500131858850971435",
                "304821208644161892629692801651297352170",
                "222008325521717911926671620388751190066",
                "2475160411350359381344389114973539819",
                "13272895742827941864010673580778240578",
                "241052143385281271848629075758522477959",
                "331000839337365724571815160687651557729",
                "228439078923818719090112943470032427422",
                "74387082046443178366377574784278952042",
                "325863489862828762800076405579407644213",
                "94989224821843557218848024086817141339",
                "49783575525568689744929910066421538495",
                "77986545761946537405229450952258036305",
                "211396000077914890137986256458079054265",
                "162897786506477548529509607732487400102",
                "322064036455970532549900314725196445640"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-19968-f3503156",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/assimp/assimp/commit/ee77bb09a42a49843ac85ef64c14d2328b251df1",
        "target": {
            "file": "code/AssetLib/LWO/LWOLoader.h"
        }
    }
]
vanir_signatures_modified
"2026-08-22T09:15:49Z"