← Back

CVE-2026-26200

nvd nist
Published: Feb 19, 2026Modified: Feb 20, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.

Affected (1)

Products: Hdfgroup: Hdf5
1 product
Hdf5
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.14.4.2

References (1)

Source: security-advisories@github.com
ExploitThird Party Advisory

Timeline

No history available yet.