A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82591.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-122"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"last_affected": "6.0.0"
},
{
"introduced": "6.0.1"
},
{
"last_affected": "6.0.1"
},
{
"introduced": "6.0.2"
},
{
"last_affected": "6.0.2"
}
]
}
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1219.0,
"function_hash": "186752811311669738618565339004570772711"
},
"id": "CVE-2026-82591-308bdb3f",
"target": {
"function": "MD5Importer::MakeDataUnique",
"file": "code/AssetLib/MD5/MD5Loader.cpp"
},
"source": "https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"336022327407125324326199491973988077562",
"297438913925782871772466604183249911055",
"328388650969745820897817815714129855240",
"322467812423735289886014009447658605324",
"188718179704516331714409943675816551252",
"99474891215608315379038145059286517643",
"228728000507000326959856317018482317386",
"336225018236052098217716795916314958489",
"130335675576326603463986405197172146494",
"133580773314418692296294101738932561394",
"57963952560273292508490427573128138725",
"100185357309505874785944618069549880072",
"191277960294010541431340693934993592228",
"143419097020061722898651005836583263178",
"107890206896442704621817795245694980233",
"187114280304163212931797159705814708458",
"318516335233516444248838273122689141593",
"148839545812466620908927536519612077227",
"233709397925019812295996600830287953750",
"281230561186136765617638722645800705674",
"204343783042689885586598724063410123154",
"16738211286590249213981029304353972319",
"94227493758669431775549154894217071623",
"172015575142415890432276658514362897746",
"48172625832181660792403101506707155391",
"124405747315649928598237121559604472497",
"272399109318899038456530773795219672578",
"4520508470707959753942044726018475422",
"119341724021477252051477894831276760897",
"110070062342379702976114277372106996192",
"111705309254423810072488757791897291017",
"219020178492622720468609051086011555081",
"153787677621696872689579455959355887869",
"303048065285123337198797847651469003490"
],
"threshold": 0.9
},
"id": "CVE-2026-82591-c0b4605d",
"target": {
"file": "code/AssetLib/MD5/MD5Loader.cpp"
},
"source": "https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82591.json"
"2026-09-01T08:20:15Z"