CVE-2026-82591

Source
https://cve.org/CVERecord?id=CVE-2026-82591
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82591.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82591
Downstream
Published
2026-08-30T22:45:13.715Z
Modified
2026-09-01T08:20:15.436345Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflow
Details

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82591.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ]
}
References

Affected packages

Git / github.com/assimp/assimp

Affected ranges

Type
GIT
Repo
https://github.com/assimp/assimp
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "last_affected": "6.0.0"
        },
        {
            "introduced": "6.0.1"
        },
        {
            "last_affected": "6.0.1"
        },
        {
            "introduced": "6.0.2"
        },
        {
            "last_affected": "6.0.2"
        }
    ]
}

Affected versions

6.*
6.0.0
6.0.1
6.0.2
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.0.4
v6.0.5

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1219.0,
            "function_hash": "186752811311669738618565339004570772711"
        },
        "id": "CVE-2026-82591-308bdb3f",
        "target": {
            "function": "MD5Importer::MakeDataUnique",
            "file": "code/AssetLib/MD5/MD5Loader.cpp"
        },
        "source": "https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "336022327407125324326199491973988077562",
                "297438913925782871772466604183249911055",
                "328388650969745820897817815714129855240",
                "322467812423735289886014009447658605324",
                "188718179704516331714409943675816551252",
                "99474891215608315379038145059286517643",
                "228728000507000326959856317018482317386",
                "336225018236052098217716795916314958489",
                "130335675576326603463986405197172146494",
                "133580773314418692296294101738932561394",
                "57963952560273292508490427573128138725",
                "100185357309505874785944618069549880072",
                "191277960294010541431340693934993592228",
                "143419097020061722898651005836583263178",
                "107890206896442704621817795245694980233",
                "187114280304163212931797159705814708458",
                "318516335233516444248838273122689141593",
                "148839545812466620908927536519612077227",
                "233709397925019812295996600830287953750",
                "281230561186136765617638722645800705674",
                "204343783042689885586598724063410123154",
                "16738211286590249213981029304353972319",
                "94227493758669431775549154894217071623",
                "172015575142415890432276658514362897746",
                "48172625832181660792403101506707155391",
                "124405747315649928598237121559604472497",
                "272399109318899038456530773795219672578",
                "4520508470707959753942044726018475422",
                "119341724021477252051477894831276760897",
                "110070062342379702976114277372106996192",
                "111705309254423810072488757791897291017",
                "219020178492622720468609051086011555081",
                "153787677621696872689579455959355887869",
                "303048065285123337198797847651469003490"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82591-c0b4605d",
        "target": {
            "file": "code/AssetLib/MD5/MD5Loader.cpp"
        },
        "source": "https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82591.json"
vanir_signatures_modified
"2026-09-01T08:20:15Z"