vtk
VTK is an open-source toolkit for 3D computer graphics, image processing, and visualization
Activity
- Latest release
- 1mo ago
- Total releases
- 27
- Cadence
- ~3 months
- Last 12 months
- 6
Details
- License
- BSD-3-Clause
- First release
- Jan 31, 2018
| Version | Released | |
|---|---|---|
9.7.0
minor
|
9.7.0
minor
Dependencies (3)
|
|
9.7.0rc4
pre
|
9.7.0rc4
pre
Dependencies (3)
|
|
9.7.0rc3
pre
|
9.7.0rc3
pre
Dependencies (3)
|
|
9.6.2
patch
|
9.6.2
patch
Dependencies (3)
|
|
9.6.1
patch
|
9.6.1
patch
Dependencies (3)
|
|
9.6.0
minor
|
9.6.0
minor
Dependencies (3)
|
|
9.5.2
patch
|
9.5.2
patch
Dependencies (3)
|
|
9.5.1
patch
|
9.5.1
patch
Dependencies (3)
|
|
9.5.0
minor
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.5.0
minor
Dependencies (3)
|
|
9.4.2
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.4.2
patch
Dependencies (3)
|
|
9.4.1
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.4.1
patch
Dependencies (3)
|
|
9.4.0
minor
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.4.0
minor
Dependencies (3)
|
|
9.3.1
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.3.1
patch
Dependencies (3)
|
|
9.3.0
minor
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.3.0
minor
Dependencies (3)
|
|
9.3.20230807rc0
pre
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.3.20230807rc0
pre
Dependencies (3)
|
|
9.2.6
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.2.6
patch
Dependencies (3)
|
|
9.2.5
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.2.5
patch
Dependencies (3)
|
|
9.2.4
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.2.4
patch
Dependencies (3)
|
|
9.2.2
minor
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.2.2
minor
Dependencies (3)
|
|
9.1.0
minor
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.1.0
minor
Dependencies (3)
|
|
9.0.3
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.0.3
patch
Dependencies (5)
|
|
9.0.2
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.0.2
patch
Dependencies (5)
|
|
9.0.1
patch
3 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev |
9.0.1
patch
Dependencies (1)
|
|
9.0.0
major
4 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2021-42521
GHSA-xfhg-9pjg-xg7g
PYSEC-2022-255
Aug 26, 2022
VTK NULL pointer dereference vulnerability
High
Network
Low
None
None
There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
Fixed in
9.0.1
References
Updated Nov 18, 2024 · Source: OSV.dev |
9.0.0
major
Dependencies (1)
|
|
8.1.2
patch
4 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2021-42521
GHSA-xfhg-9pjg-xg7g
PYSEC-2022-255
Aug 26, 2022
VTK NULL pointer dereference vulnerability
High
Network
Low
None
None
There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
Fixed in
9.0.1
References
Updated Nov 18, 2024 · Source: OSV.dev |
8.1.2
patch
|
|
8.1.1
patch
4 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2021-42521
GHSA-xfhg-9pjg-xg7g
PYSEC-2022-255
Aug 26, 2022
VTK NULL pointer dereference vulnerability
High
Network
Low
None
None
There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
Fixed in
9.0.1
References
Updated Nov 18, 2024 · Source: OSV.dev |
8.1.1
patch
|
|
8.1.0
initial
4 CVEs
CVE-2025-57108
PYSEC-2025-226
Oct 31, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57107
PYSEC-2025-225
Oct 31, 2025
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-57106
PYSEC-2025-224
Oct 31, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.2.2
9.2.4
9.2.5
9.2.6
+ 7 more Show less
9.3.0
9.3.1
9.3.20230807rc0
9.4.0
9.4.1
9.4.2
9.5.0
Fixed in
9.5.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2021-42521
GHSA-xfhg-9pjg-xg7g
PYSEC-2022-255
Aug 26, 2022
VTK NULL pointer dereference vulnerability
High
Network
Low
None
None
There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application. Affected versions
8.1.0
8.1.1
8.1.2
9.0.0
Fixed in
9.0.1
References
Updated Nov 18, 2024 · Source: OSV.dev |
8.1.0
initial
|