Logo
vulnerabilityCVE-2026-10230
Name
CVE-2026-10230
Source
NVD ( link)Debian ( link)
Description
A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
assimp
Exploitable

Vulnerability Ratings#


1.9
CVSSv4
5.3
CVSSv31
4.3
CVSSv2
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.0.2
Exploitable