A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

Project Subscriptions

Vendors Products
Autodesk Subscribe
Shared Components Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
Title IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products
First Time appeared Autodesk
Autodesk shared Components
Weaknesses CWE-674
CPEs cpe:2.3:a:autodesk:shared_components:1.11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:shared_components:2.0.4.1:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk shared Components
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-09-02T14:37:05.500Z

Reserved: 2026-06-30T14:44:00.497Z

Link: CVE-2026-14255

cve-icon Vulnrichment

Updated: 2026-09-02T14:36:57.565Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T15:17:37.403

Modified: 2026-09-03T16:44:01.873

Link: CVE-2026-14255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:00:04Z

Weaknesses