CVE-2025-57106

K

itware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.

References
Link Resource
https://gitlab.kitware.com/vtk/vtk/-/issues/19733 Exploit Issue Tracking Third Party Advisory
https://gitlab.kitware.com/vtk/vtk/-/issues/19734 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vtk:vtk:*:*:*:*:*:*:*:*

History

05 Nov 2025, 19:44

Type Values Removed Values Added
References () https://gitlab.kitware.com/vtk/vtk/-/issues/19733 - () https://gitlab.kitware.com/vtk/vtk/-/issues/19733 - Exploit, Issue Tracking, Third Party Advisory
References () https://gitlab.kitware.com/vtk/vtk/-/issues/19734 - () https://gitlab.kitware.com/vtk/vtk/-/issues/19734 - Exploit, Issue Tracking, Third Party Advisory
First Time Vtk
Vtk vtk
CPE cpe:2.3:a:vtk:vtk:*:*:*:*:*:*:*:*

31 Oct 2025, 19:15

Type Values Removed Values Added
CWE CWE-122
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

31 Oct 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-31 15:15

Updated : 2025-11-05 19:44


NVD link : CVE-2025-57106

Mitre link : CVE-2025-57106

CVE.ORG link : CVE-2025-57106


JSON object : View

Products Affected
CWE
CWE-122

Heap-based Buffer Overflow