PYPI · JULY 2026 · EARLY WARNING

Memory-Safety Vulnerability in Open Babel's MOPAC Parser

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-55F6-PF8R-C2F4Severity: HIGH

An early warning has been issued regarding a memory-safety vulnerability in Open Babel's MOPAC output parser, which reportedly allows an out-of-bounds write into the `translationVectors[]` array. Users of openbabel (pypi) version 3.1.1 or earlier are advised to upgrade to Open Babel 3.2.0 or later.

What happened

An early warning has been issued for a memory-safety vulnerability in Open Babel's MOPAC output parser. The vulnerability reportedly allows an out-of-bounds write into the `translationVectors[]` array when processing the 'UNIT CELL TRANSLATION' block of a specially crafted input file. This issue is tracked under GHSA-55F6-PF8R-C2F4.

The vulnerability is under investigation and has been classified internally as a critical CVE. The affected component is openbabel (pypi) version 3.1.1 or earlier. It is recommended that users upgrade to Open Babel 3.2.0 or later to mitigate potential risks.

For more detailed information, please consult the primary source at https://github.com/openbabel/openbabel/security/advisories/GHSA-55f6-pf8r-c2f4. Further details regarding the severity, exact version ranges, and attribution are currently under investigation and should be confirmed through primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If openbabel is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats