Slic3r is a widely used open-source slicing engine for 3D printing that converts CAD models into printer-executable toolpaths, with vulnerabilities concentrated in its core library and command-line tool. The exposure reflects the software's role parsing untrusted input files and performing memory-intensive geometric operations, clustering around out-of-bounds reads, NULL-pointer dereferences, improper input validation, and inconsistent length-parameter handling that are characteristic of C++-based mesh-processing code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slic3r over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38072HIGH An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can | Apr 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-36788HIGH A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially-crafted STL file can lead | Apr 20, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-44961MEDIUM A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attac | Mar 1, 2022 | 5.5 | 22 | NO | NO |
CVE-2020-28591MEDIUM An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AM | Mar 3, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-28590MEDIUM An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj | Apr 13, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-44962MEDIUM An out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially crafted stl file could lead to inf | Mar 1, 2022 | 5.5 | 20 | NO | NO |
CVE-2021-45846MEDIUM A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a metadata tag lacks a "type" attribute. | Jan 25, 2022 | 5.5 | 20 | NO | NO |
CVE-2021-45847MEDIUM Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file. | Jan 25, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slic3r.
Media articles that mention a CVE ID that affects a product developed by Slic3r — matched by CVE ID, not by vendor name.