VTK is a specialized visualization and 3D graphics toolkit that, despite a narrow product scope, serves as a foundational library embedded across scientific computing, medical imaging, and data-visualization applications. The durable signal in its vulnerability profile centers on low-level memory-safety and resource-handling issues, including heap-based buffer overflows, NULL-pointer dereferences, uncontrolled resource consumption, and use-after-free conditions, which are characteristic of a C++-based graphics library processing untrusted geometry and imaging data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vtk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57108CRITICAL Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operati | Oct 31, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-57106HIGH Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template funct | Oct 31, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-57107HIGH Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy con | Oct 31, 2025 | 7.1 | 24 | NO | NO |
CVE-2021-42521HIGH There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlD | Aug 25, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vtk.
Media articles that mention a CVE ID that affects a product developed by Vtk — matched by CVE ID, not by vendor name.