A vulnerability marked as critical has been reported in Open Asset Import Library Assimp 17c12da. Impacted is the function
Assimp::Compression::decompressBlock of the file code/Common/Compression.cpp of the component File Parser. Performing a manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-19967. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.