A stack overflow in the experimental/tinyobjloaderopt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29628.json",
"cna_assigner": "mitre"
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"211111531540036651241052570083145355657",
"4104103951293126996962537604432218752",
"265768393309540392661753294181924623284",
"215684235228023192217754378717255659742"
],
"threshold": 0.9
},
"id": "CVE-2026-29628-6cddb1cb",
"target": {
"file": "experimental/tinyobj_loader_opt.h"
},
"source": "https://github.com/kiyochii/tinyobjloader/commit/386b73bb8c1a855236beb73b11f45f7feac4e03a",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29628.json"
"2026-08-12T16:24:57Z"