Security Advisory

CVE-2026-42479

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-01 00:00:00
Last updated 2026-05-01 18:29:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because coordIndex values from parsed input are used as direct array indices without validation against the size of the coordinate array during geometry processing.