Admesh is a compact STL mesh-processing utility with a focused vulnerability footprint centered on its core application and recurring memory-safety issues spanning heap-based buffer overflows, improper bounds checking, and array indexing errors. These weakness classes reflect the low-level geometric computation and file-format parsing demands inherent to mesh manipulation; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Admesh Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38072HIGH An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can | Apr 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-25033HIGH ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a. | May 8, 2022 | 8.1 | 27 | NO | NO |
CVE-2026-2653HIGH A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in | Feb 18, 2026 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Admesh Project.
Media articles that mention a CVE ID that affects a product developed by Admesh Project — matched by CVE ID, not by vendor name.