A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
References
| Link | Resource |
|---|---|
| https://github.com/admesh/admesh/ | Product |
| https://github.com/admesh/admesh/issues/65 | Issue Tracking |
| https://github.com/admesh/admesh/issues/65#issuecomment-3804571402 | Issue Tracking |
| https://github.com/user-attachments/files/24878279/id.000035.sig.06.src.000550.time.910126.execs.241742.op.havoc.rep.5.zip | Exploit |
| https://vuldb.com/?ctiid.346450 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346450 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.752596 | Third Party Advisory VDB Entry |
Configurations
History
20 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Admesh Project
Admesh Project admesh |
|
| CPE | cpe:2.3:a:admesh_project:admesh:*:*:*:*:*:*:*:* | |
| References | () https://github.com/admesh/admesh/ - Product | |
| References | () https://github.com/admesh/admesh/issues/65 - Issue Tracking | |
| References | () https://github.com/admesh/admesh/issues/65#issuecomment-3804571402 - Issue Tracking | |
| References | () https://github.com/user-attachments/files/24878279/id.000035.sig.06.src.000550.time.910126.execs.241742.op.havoc.rep.5.zip - Exploit | |
| References | () https://vuldb.com/?ctiid.346450 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346450 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.752596 - Third Party Advisory, VDB Entry | |
| Summary |
|
18 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-18 11:16
Updated : 2026-02-20 16:16
NVD link : CVE-2026-2653
Mitre link : CVE-2026-2653
CVE.ORG link : CVE-2026-2653
JSON object : View
Products Affected
admesh_project
- admesh
