CVE-2026-39020
Deferred Deferred - Pending Action

Denial of Service in Wings3D via Wavefront OBJ File

Vulnerability report for CVE-2026-39020, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: MITRE

Description

An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wings3d wings3d 2.4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-39020 is a denial-of-service vulnerability in Wings3D v2.4.1 caused by improper handling of IEEE 754 special float values like NaN, Inf, and -Inf in Wavefront OBJ files. The application crashes immediately when parsing crafted files due to an unhandled exception in its custom float parser.

Detection Guidance

To detect this vulnerability, monitor for crashes in Wings3D when importing Wavefront OBJ files. Check application logs for unhandled function_clause exceptions related to str2float_2/2 in e3d_obj.erl. Test suspicious OBJ files containing IEEE 754 special float values (NaN, Inf, -Inf) to observe crashes.

Impact Analysis

This vulnerability allows a local attacker to crash Wings3D by tricking a user into opening a malicious OBJ file. The crash may result in loss of unsaved work, but does not allow code execution or privilege escalation.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it only causes a denial of service by crashing the application. It does not involve data exposure, unauthorized access, or loss of sensitive information that these regulations typically address.

Mitigation Strategies

Avoid opening untrusted Wavefront OBJ files in Wings3D. Update to a patched version if available. Implement file validation to block OBJ files containing IEEE 754 special float values. Consider using alternative software for OBJ file processing until the issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39020. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart