


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in VrmlData_IndexedFaceSet::TShape in the VRML V2.0 parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a deni…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 20:05:47
Source:
nvd.nist.gov
Enterprise Applications
A vulnerability was discovered in the VrmlData_IndexedFaceSet::TShape function within the VRML V2.0 parser of Open CASCADE Technology (OCCT) version V8_0_0_rc5. The vulnerability allows attackers to cause a denial of service by providing a specially crafted VRML file. The issue stems from malformed VRML input that can trigger dereferencing of a corrupt or unvalidated pointer during shape construction in the libTKDEVRML.so library. This represents a memory corruption vulnerability that could potentially lead to application crashes when processing untrusted VRML files.
Technical details
Mitigation steps:
Affected products:
Open CASCADE Technology (OCCT)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42478
https://gist.github.com/sgInnora/dfba083d04906283e9c92aea78e2d94a
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
