CVE-2026-2653
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
18/02/2026
Last modified:
20/02/2026
Description
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:admesh_project:admesh:*:*:*:*:*:*:*:* | 0.98.5 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/admesh/admesh/
- https://github.com/admesh/admesh/issues/65
- https://github.com/admesh/admesh/issues/65#issuecomment-3804571402
- https://github.com/user-attachments/files/24878279/id.000035.sig.06.src.000550.time.910126.execs.241742.op.havoc.rep.5.zip
- https://vuldb.com/?ctiid_346450=
- https://vuldb.com/?id_346450=
- https://vuldb.com/?submit_752596=



