MEDIUMVulnerability

CVE-2026-82591

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00124
cve_id
CVE-2026-82591
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-08-30T23:17:08.137
last_modified
2026-09-01T20:48:22.513
epss_percentile
0.0245

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Heap-based Buffer Overflow
[Weakness]Improper Restriction of Operations within the Bounds of a Memory Buffer

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82591 — Ninja Signal Threat Intelligence | Ninja Signal