Open Babel is a widely embedded chemistry and molecular-modeling library that converts between chemical file formats and provides computational chemistry functionality across research software, bioinformatics platforms, and drug-discovery workflows. Despite a narrow product portfolio, the library's deep integration into scientific computing environments and its role in processing untrusted chemical data files creates a meaningful attack surface. Vulnerabilities affecting the library cluster around memory-safety issues—including buffer overflows, out-of-bounds writes, heap-based corruption, and NULL-pointer dereferences—that arise from the parsing and manipulation of complex chemical file structures and lack of formal bounds checking. These weakness classes reflect the C/C++ implementation heritage and the challenge of safely handling variable-length and format-diverse input. Defenders working in research and drug-discovery environments should track Open Babel releases and treat file-processing pipelines that accept external chemical data as requiring input validation and sandboxing; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbabel over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2705HIGH A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 F | Feb 19, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-2704HIGH A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d | Feb 19, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-10997HIGH A flaw has been found in Open Babel up to 3.1.1. Impacted is the function ChemKinFormat::CheckSpecies of the file /src/formats/chemkinformat.cpp. Executing manipulation can lead to | Sep 26, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-10996HIGH A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of the file /src/formats/smilesformat.cpp. Performing manipulati | Sep 26, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-10995HIGH A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zips | Sep 26, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-10994HIGH A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use afte | Sep 26, 2025 | 7.8 | 26 | NO | NO |
CVE-2022-44451HIGH A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead | Jul 21, 2023 | 7.8 | 26 | NO | NO |
CVE-2022-42885HIGH A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead | Jul 21, 2023 | 7.8 | 26 | NO | NO |
CVE-2022-41793HIGH An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arb | Jul 21, 2023 | 7.8 | 26 | NO | NO |
CVE-2022-46291HIGH Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A s | Jul 21, 2023 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbabel.
Media articles that mention a CVE ID that affects a product developed by Openbabel — matched by CVE ID, not by vendor name.