CVE-2025-4640: Pointcloudlibrary Pcl

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

Affected products

Published 2025-05-14. Last modified 2026-06-17.