CGAL is a specialized computational-geometry library embedded in scientific computing, computer graphics, and robotics applications, where its narrow product scope masks broad downstream deployment across research and production systems. The vendor's vulnerability exposure concentrates in a single core product—the Computational Geometry Algorithms Library—and a meaningful share of its disclosures reach serious severity, reflecting the numerical and memory-access complexity inherent to geometric algorithms implemented in C++. Recurring weakness classes including improper array-index validation, out-of-bounds reads, and type-confusion issues are characteristic of memory-unsafe implementations handling complex data structures and algorithmic state. Defenders should treat CGAL patches as supply-chain priorities for dependent projects and inventory applications that link this library; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cgal over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28607HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 30 | NO | NO |
CVE-2020-35636CRITICAL A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB re | Mar 4, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-35628CRITICAL A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser: | Mar 4, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-28601CRITICAL A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::re | Mar 4, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-28628HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-28627HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-28622HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-28618HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-28615HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-28614HIGH Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds | Apr 18, 2022 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cgal.
Media articles that mention a CVE ID that affects a product developed by Cgal — matched by CVE ID, not by vendor name.