CVE-2026-14255 PUBLISHED

IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products

Assigner: autodesk
Reserved: 30.06.2026 Published: 02.09.2026 Updated: 02.09.2026

A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 5.5

Product Status

Vendor Autodesk
Product Shared Components
Versions Default: unaffected
  • affected from 1.11.0 to 1.12.0 (excl.)
  • affected from 2.0.0 to 2.2.0 (excl.)

References

Problem Types

  • CWE-674 Uncontrolled Recursion CWE

Impacts

  • CAPEC-230 Serialized Data with Nested Payloads