Back

MEDIUM

MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

Published Aug 1, 2025

Description

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 1, 2025
Updated Aug 1, 2025
Reserved Jun 24, 2025

CISA Vulnrichment

Updated Aug 1, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Aug 1, 2025
Updated Aug 1, 2025