Blender's vulnerability profile centers on a single, widely used open-source 3D modeling and animation application that has become a standard tool across creative industries and digital content production. The recurring exposure stems from file-parsing and data-handling complexity inherent to Blender's support for diverse model formats and scene structures, manifesting through integer overflow, code-injection conditions, link-following flaws, and memory-safety issues that arise when processing untrusted project files and external assets. A moderate share of the vendor's disclosures acquire public exploit code, reflecting the accessibility of Blender to researchers and the relative ease of crafting malicious assets that trigger parsing vulnerabilities. Defenders should treat Blender as a supply-chain risk in environments where project files or assets come from untrusted sources and ensure timely patching for creative workflows; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blender over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3850HIGH Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA. | Nov 6, 2009 | 9.3 | 42 | NO | YES |
CVE-2026-60103MEDIUM Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file wi | Jul 13, 2026 | 6.1 | 29 | NO | NO |
CVE-2005-3302HIGH Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval | Oct 24, 2005 | 7.3 | 29 | NO | YES |
CVE-2022-2832HIGH A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity. | Aug 16, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-2833HIGH Endless Infinite loop in Blender-thumnailing due to logical bugs. | Aug 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-2831HIGH A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption. | Aug 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2017-2899HIGH An exploitable integer overflow exists in the TIFF loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.tif' file can cause an in | Apr 24, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-12099HIGH An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can | Apr 24, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-12086HIGH An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause | Apr 24, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-2900HIGH An exploitable integer overflow exists in the PNG loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.png' file can cause an int | Apr 24, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blender.
Media articles that mention a CVE ID that affects a product developed by Blender — matched by CVE ID, not by vendor name.