An issue was discovered in VrmlData_IndexedFaceSet::TShape in the VRML V2.0 parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because malformed VRML input can trigger dereference of a corrupt or unvalidated pointer during shape construction in libTKDEVRML.so.
References
| Link | Resource |
|---|---|
| https://gist.github.com/sgInnora/dfba083d04906283e9c92aea78e2d94a | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
01 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-125 |
01 May 2026, 17:48
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://gist.github.com/sgInnora/dfba083d04906283e9c92aea78e2d94a - Third Party Advisory | |
| CWE | CWE-476 | |
| First Time |
Opencascade
Opencascade open Cascade Technology |
|
| CPE | cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:rc4:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:*:*:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:rc5:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:rc3:*:*:*:*:*:* cpe:2.3:a:opencascade:open_cascade_technology:8.0.0:rc1:*:*:*:*:*:* |
01 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-01 15:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-42478
Mitre link : CVE-2026-42478
CVE.ORG link : CVE-2026-42478
JSON object : View
Products Affected
opencascade
- open_cascade_technology
