{"id":"CVE-2025-10998","aliases":["GHSA-j9pp-7wfg-q7fj","PYSEC-2026-2782"],"url":"https://o3.security/vulnerability/CVE-2025-10998","summary":"Open Babel chemkinformat.cpp ReadReactionQualifierLines null pointer dereference","details":"A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReactionQualifierLines of the file /src/formats/chemkinformat.cpp. The manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used.","published":"2025-09-26T03:02:07.042Z","modified":"2026-08-12T03:51:26.622855445Z","cvss":null,"epss":{"score":0.00206,"percentile":0.10642,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"openbabel","fixedVersion":"3.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10998.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10998"},{"type":"ADVISORY","url":"https://vuldb.com/?id.325926"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.654063"},{"type":"REPORT","url":"https://github.com/openbabel/openbabel/issues/2829"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.325926"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/22318526/poc.zip"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.622855445Z"}}