Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://gitlab.kitware.com/vtk/vtk/-/issues/19735 |
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vtk
Vtk vtk |
|
| Vendors & Products |
Vtk
Vtk vtk |
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Thu, 30 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-30T20:56:40.033Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57109
Updated: 2025-10-30T20:56:35.172Z
Status : Deferred
Published: 2025-10-30T19:16:35.207
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-57109
No data.
OpenCVE Enrichment
Updated: 2025-10-31T10:14:03Z