CVE-2025-4640: Pointcloudlibrary Pcl
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.
Affected products
Published 2025-05-14. Last modified 2026-06-17.