CVE-2025-15647
CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data to trigger an out-of-bounds array access that crashes the calling process.
| CWE | CWE-125 |
| Vendor | artem-ogre |
| Product | cdt |
| Published | Sep 5, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for artem-ogre cdt
Be the first to know when new medium vulnerabilities affecting artem-ogre cdt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
artem-ogre / CDT
0 < 1.4.5
References
github.com: https://github.com/artem-ogre/CDT/issues/212 github.com: https://github.com/artem-ogre/CDT/commit/bf0d11ebfe3da0da72aed91816f665aef1b447cc github.com: https://github.com/artem-ogre/CDT/blob/1.4.4/CDT/include/CDTUtils.hpp#L175 github.com: https://github.com/artem-ogre/CDT/releases/tag/1.4.5 github.com: https://github.com/artem-ogre/CDT vulncheck.com: https://www.vulncheck.com/advisories/cdt-before-1.4.5-out-of-bounds-read-via-opposedvertexind
Credits
๐ Vlatko Kosturjak