CVE-2025-10021 is a Use of Uninitialized Variable vulnerability in Open Design Alliance Drawings SDK static versions prior to 2026.12. Specifically, the application may attempt to access the OdString::kEmpty object before its proper initialization due to static initialization order issues. This can lead to application crashes on startup, causing a denial of service, and potentially memory corruption or arbitrary code execution under specific conditions. The vulnerability has a CVSSv4 score of 7.0 (High), indicating a local attack vector with low attack complexity, requiring no privileges or user interaction. The primary impact is high availability loss, though integrity and confidentiality impacts are currently unassessed. There is no evidence of active exploitation, nor are there public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Open Design Alliance | ODA Drawings SDK - All Versions < 2026.12 | >= 0, < 2026.12CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.