Skip to content
AutodeskCVE-2026-14255

Autodesk Shared Components: denial of service

Medium5.5CVE-2026-14255 · Published Sep 2, 2026 · updated Sep 3, 2026

A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

Autodesk advisory

Affected versions

PackageAffectedFixed in
Shared Components
Product
>= 1.11.0, < 1.12.01.12.0
>= 2.0.0, < 2.2.02.2.0
Details and references

More Autodesk advisories

All Autodesk
Advisory
Autodesk Fusion: information disclosure
High8.6Sep 10
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: memory corruption
High7.8Aug 24
Autodesk 3ds Max: denial of service
Medium5.5Aug 24
Autodesk 3ds Max: out-of-bounds read
Medium5.3Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.