A stack overflow in the experimental/tinyobjloaderopt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29628.json"
}"2026-08-07T21:53:36Z"
[
{
"target": {
"file": "experimental/tinyobj_loader_opt.h"
},
"digest": {
"line_hashes": [
"211111531540036651241052570083145355657",
"4104103951293126996962537604432218752",
"265768393309540392661753294181924623284",
"215684235228023192217754378717255659742"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-29628-6cddb1cb",
"source": "https://github.com/kiyochii/tinyobjloader/commit/386b73bb8c1a855236beb73b11f45f7feac4e03a"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29628.json"