{"id":"CVE-2025-10995","aliases":["GHSA-8j3x-m868-cpw8","PYSEC-2026-2776"],"url":"https://o3.security/vulnerability/CVE-2025-10995","summary":"Open Babel zipstreamimpl.h underflow memory corruption","details":"A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.","published":"2025-09-26T02:02:10.346Z","modified":"2026-08-12T03:51:47.333043151Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"openbabel","fixedVersion":"3.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10995.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10995"},{"type":"ADVISORY","url":"https://vuldb.com/?id.325923"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.654059"},{"type":"REPORT","url":"https://github.com/openbabel/openbabel/issues/2832"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.325923"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/22318572/poc.zip"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.333043151Z"}}