MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3. | |
Title | MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit | |
Weaknesses | CWE-121 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-01T17:57:56.221Z
Updated: 2025-08-01T18:22:16.665Z
Reserved: 2025-06-24T03:50:36.795Z
Link: CVE-2025-53009

Updated: 2025-08-01T18:22:04.969Z

Status : Awaiting Analysis
Published: 2025-08-01T18:15:54.463
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-53009

No data.