Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Assimp

First CVE: Jan 1, 2022Active for: 5 yearsTotal CVEs: 47
31.4
VTI Score
Medium

Assimp is a widely embedded open-source asset-import library that converts 3D model file formats from external sources into in-memory representations for graphics applications and game engines. Despite a very narrow product scope, the library's prominence in the 3D graphics pipeline means vulnerabilities can propagate to any application that parses untrusted model files, creating a distributed attack surface across game development, animation, CAD, and visualization software. The vendor's vulnerability profile clusters durably around memory-safety issues—out-of-bounds reads and writes, heap buffer overflows, and classic buffer-overflow conditions—that arise from parsing complex and variable-length 3D file formats without exhaustive bounds checking. The low severity tendency and negligible exploitation profile reflect the library's typical deployment context: file parsing of offline or design-time assets rather than live network-facing operations, though defenders should still track this vendor's releases when Assimp is integrated into file-upload or content-pipeline workflows. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
9.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Assimp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2022
4 years ago
Most Recent CVE
Jan 18, 2026
187 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-11277HIGH
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp.
Oct 5, 20257.827NONO
CVE-2022-45748HIGH
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
Jan 20, 20238.827NONO
CVE-2025-3015HIGH
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the fil
Mar 31, 20258.826NONO
CVE-2025-2152CRITICAL
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of
Mar 10, 20259.826NONO
CVE-2025-15538HIGH
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of th
Jan 18, 20267.825NONO
CVE-2025-11275HIGH
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/
Oct 5, 20257.825NONO
CVE-2025-2592HIGH
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file
Mar 21, 20258.825NONO
CVE-2025-2151HIGH
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.
Mar 10, 20258.825NONO
CVE-2025-5204HIGH
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump_3DGS_MDL7 of the file assim
May 26, 20257.824NONO
CVE-2025-2752HIGH
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/f
Mar 25, 20258.824NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
38%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local31 (66.0%)
Network16 (34.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None28 (59.6%)
Unknown0 (0.0%)
Required19 (40.4%)
Privileges Required
Low24 (51.1%)
High0 (0.0%)
None23 (48.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Assimp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Assimp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Assimp's Products

View all 3 CNAs →

Top CWEs