← Vulnerability feed

Vulnerability record · CVE-2026-26200 · published 19 February 2026

CVE-2026-26200: Hdfgroup hdf5 heap-based buffer overflow vulnerability

Hdfgroup · Hdf5

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.

7.8 CVSS 3.1 High EPSS 0.36% · top 72.5% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
15 Jul 2026Last modified by NVD

Description

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-26200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-32608Hdfgroup hdf5 out-of-bounds write vulnerabilityHDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service …EPSS 0.67%9.8CVE-2024-33874Hdfgroup hdf5 classic buffer overflow vulnerabilityHDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.EPSS 0.93%9.8CVE-2024-32621Hdfgroup hdf5 heap-based buffer overflow vulnerabilityHDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), re…EPSS 0.93%9.8CVE-2024-32611Hdfgroup hdf5 use of uninitialized resource vulnerabilityHDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.EPSS 0.95%9.8CVE-2024-32615Hdfgroup hdf5 out-of-bounds write vulnerabilityHDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an init…EPSS 1.1%9.8CVE-2024-29164Hdfgroup hdf5 stack-based buffer overflow vulnerabilityHDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial o…EPSS 0.86%9.8CVE-2024-29159Hdfgroup hdf5 classic buffer overflow vulnerabilityHDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial …EPSS 0.92%9.8CVE-2024-29157Hdfgroup hdf5 heap-based buffer overflow vulnerabilityHDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of servic…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2026-26200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.