Back

MEDIUM

Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference

Published May 31, 2026

Description

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

Affected products

Remediation

Red Hat statement

A Moderate impact null pointer dereference flaw was found in Assimp's glTFImporter component. This vulnerability allows a local attacker to trigger a denial of service by providing a specially crafted glTF file, causing applications utilizing Assimp to crash. The local nature of the attack limits its overall impact.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 31, 2026
Updated Jun 1, 2026
Reserved May 31, 2026
CISA Vulnrichment
Updated Jun 1, 2026
NVD
Status Deferred
Modified Jul 22, 2026
Red Hat
Severity Moderate
Public date May 31, 2026