Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Assimp — Vulnerabilities & Security Advisories 51

All 51 CVE vulnerabilities found in Assimp, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the Assimp open source library, maintained by the Assimp community. It aggregates security vulnerabilities categorized by their underlying weakness types, providing a centralized view of issues affecting this widely used 3D file format processing engine. The collection covers a broad historical range of disclosed flaws, from early initial releases to recent patches, ensuring comprehensive coverage of the library's security posture over time. Here, users can track advisory timelines from the primary vendor to understand the lifecycle of reported bugs and the speed of subsequent fixes. By examining these entries, developers and security analysts can gain deeper insights into specific weakness classes that frequently impact Assimp, such as buffer overflows or use-after-free errors, and how they manifest in common file formats like COLLADA or glTF. The resource also allows for a detailed look up of a product's vulnerability history, enabling teams to assess the cumulative risk profile of using Assimp in their software stack. This structured approach facilitates better risk management and helps integration engineers prioritize updates. Whether you are auditing existing deployments or evaluating the library for new projects, this aggregation serves as a practical reference for understanding the evolving security landscape of Assimp, highlighting recurring patterns and critical areas requiring attention to maintain application integrity and data safety against potential exploitation vectors.

Vendor: Open Asset Import Library

CVE IDTitleCVSSSeverityPublished
CVE-2026-14610 Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow CWE-122 5.3 Medium2026-07-03
CVE-2026-14604 Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double free CWE-415 6.3 Medium2026-07-03
CVE-2025-15666 Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow CWE-122 5.3 Medium2026-07-01
CVE-2026-10233 Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds CWE-125 3.3 Low2026-06-01
CVE-2026-10232 Assimp ASE File scene.cpp ~aiNode use after free CWE-416 5.3 Medium2026-06-01
CVE-2026-10231 Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflow CWE-122 5.3 Medium2026-06-01
CVE-2026-10230 Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow CWE-122 5.3 Medium2026-06-01
CVE-2026-10229 Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow CWE-122 5.3 Medium2026-06-01
CVE-2026-10201 Assimp UV Channel FBXExporter.cpp WriteObjects divide by zero CWE-369 3.3 Low2026-05-31
CVE-2026-10200 Assimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflow CWE-122 5.3 Medium2026-05-31
CVE-2026-10199 Assimp glTF2Asset.h LazyDict null pointer dereference CWE-476 3.3 Low2026-05-31
CVE-2026-10198 Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference CWE-476 3.3 Low2026-05-31
CVE-2026-10197 Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference CWE-476 3.3 Low2026-05-31
CVE-2025-15538 Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free CWE-416 5.3 Medium2026-01-18
CVE-2025-11277 Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow CWE-122 5.3 Medium2025-10-05
CVE-2025-11275 Open Asset Import Library Assimp OpenDDLParserUtils.h getNextSeparator heap-based overflow CWE-122 5.3 Medium2025-10-05
CVE-2025-11274 Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resources CWE-770 3.3 Low2025-10-05
CVE-2025-6120 Open Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflow CWE-122 5.3 Medium2025-06-16
CVE-2025-6119 Open Asset Import Library Assimp BVHLoader.cpp ReadNodeChannels use after free CWE-416 5.3 Medium2025-06-16
CVE-2025-5204 Open Asset Import Library Assimp MDLMaterialLoader.cpp ParseSkinLump_3DGS_MDL7 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5203 Open Asset Import Library Assimp ParsingUtils.h SkipSpaces out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5202 Open Asset Import Library Assimp HL1MDLLoader.cpp validate_header out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5201 Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5200 Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5169 Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_3DGS_MDL345 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5168 Open Asset Import Library Assimp MDLLoader.cpp ImportUVCoordinate_3DGS_MDL345 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5167 Open Asset Import Library Assimp LWOLoader.h GetS0 out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5166 Open Asset Import Library Assimp MDC File Parser MDCLoader.cpp InternReadFile out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-5165 Open Asset Import Library Assimp MDCLoader.cpp ValidateSurfaceHeader out-of-bounds CWE-125 3.3 Low2025-05-26
CVE-2025-3549 Open Asset Import Library Assimp File MD3Loader.cpp ValidateSurfaceHeaderOffsets heap-based overflow CWE-122 5.3 Medium2025-04-14

All 51 known CVE vulnerabilities affecting Assimp with full Chinese analysis, references, and POCs where available.