


Perceptive Security
SOC/SIEM Consultancy

Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_Reader::ReadAscii bec…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 20:05:47
Source:
nvd.nist.gov
Enterprise Applications
Two heap-based out-of-bounds read vulnerabilities exist in Open CASCADE Technology (OCCT) V8_0_0_rc5 STL ASCII file parser. The vulnerabilities occur in RWStl_Reader::ReadAscii function due to improper length validation of buffers from Standard_ReadLineBuffer::ReadLine(). Attackers can exploit this by convincing victims to open malicious STL files with extremely short lines. The vulnerability can lead to denial of service or information disclosure through user-assisted attacks.
Technical details
Mitigation steps:
Affected products:
Open CASCADE Technology (OCCT)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42476
https://gist.github.com/sgInnora/dfba083d04906283e9c92aea78e2d94a
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
