Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

HDF5 Software Can Crash or Let Attackers Take Control

CVE-2026-26200
Summary

An attacker can exploit a bug in older versions of HDF5 software to crash it or potentially take control of a system. This affects HDF5 versions before 1.14.4-2. To fix the issue, update to version 1.14.4-2 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
hdfgroup hdf5 <= 1.14.4.2 –
Original title
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a d...
Original description
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
nvd CVSS3.1 7.8
Vulnerability type
CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026