Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
HDF5 Software Can Crash or Let Attackers Take Control
CVE-2026-26200
Summary
An attacker can exploit a bug in older versions of HDF5 software to crash it or potentially take control of a system. This affects HDF5 versions before 1.14.4-2. To fix the issue, update to version 1.14.4-2 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| hdfgroup | hdf5 | <= 1.14.4.2 | – |
Original title
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a d...
Original description
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
nvd CVSS3.1
7.8
Vulnerability type
CWE-122
Heap-based Buffer Overflow
CWE-787
Out-of-bounds Write
- https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5p2m-j456-9mr2 Exploit Third Party Advisory
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026