CVE-2025-11274

Severity CVSS v4.0:
MEDIUM
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
05/10/2025
Last modified:
08/10/2025

Description

A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:assimp:assimp:6.0.2:*:*:*:*:*:*:*