CVE-2025-11000: Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
A memory-safety vulnerability in Open Babel’s PQS parser caused an out-of-bounds (pre-buffer) read when reading a crafted input file.
References
- github.com/advisories/GHSA-m982-7q3h-r784
- github.com/openbabel/openbabel/commit/f4a5ebae
- github.com/openbabel/openbabel/issues/2826
- github.com/openbabel/openbabel/security/advisories/GHSA-m982-7q3h-r784
- github.com/user-attachments/files/22318474/poc.zip
- nvd.nist.gov/vuln/detail/CVE-2025-11000
- vuldb.com/?ctiid.325928
- vuldb.com/?id.325928
- vuldb.com/?submit.654066
Code Behaviors & Features
Detect and mitigate CVE-2025-11000 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →