GHSA-5fgf-q57f-wwqf

Suggest an improvement
Source
https://github.com/advisories/GHSA-5fgf-q57f-wwqf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5fgf-q57f-wwqf/GHSA-5fgf-q57f-wwqf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5fgf-q57f-wwqf
Withdrawn
2026-06-30T18:48:51Z
Published
2025-09-26T03:31:07Z
Modified
2026-06-30T19:00:30Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-pp85-5j63-xpq3. This link is maintained to preserve external references.

Original Description

A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.

Database specific
{
    "cwe_ids": [
        "CWE-119"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-30T18:48:51Z",
    "nvd_published_at": "2025-09-26T02:15:52Z",
    "severity": "LOW"
}
References

Affected packages

PyPI / openbabel

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.2.0

Affected versions

1.*
1.8
1.8.1
1.8.2
1.8.3
1.8.4
2.*
2.4.0
2.4.1
3.*
3.0.0a1
3.0.0
3.1.1
3.1.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5fgf-q57f-wwqf/GHSA-5fgf-q57f-wwqf.json"