Medium severity5.3NVD Advisory· Published May 31, 2026· Updated Jul 22, 2026
CVE-2026-10200
CVE-2026-10200
Description
A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/assimp&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/assimp&distro=openSUSE%20Tumbleweed
< 5.4.3-160000.4.1+ 1 more
- (no CPE)range: < 5.4.3-160000.4.1
- (no CPE)range: < 6.0.5-4.1
Patches
Vulnerability mechanics
References
5News mentions
2- Assimp: Ten Memory-Safety CVEs Disclosed Across Half-Life MDL, glTF, and FBX ParsersVypr Intelligence · Jun 1, 2026
- Assimp: Five Memory-Safety Bugs Disclosed in glTF and FBX ParsersVypr Intelligence · Jun 1, 2026