← Vulnerability feed

Vulnerability record · CVE-2026-49014 · published 27 May 2026

CVE-2026-49014: Osgeo gdal stack-based buffer overflow vulnerability

Osgeo · Gdal

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

7.8 CVSS 3.1 High EPSS 0.15% · top 96.7% CWE-121 · Stack-based buffer overflow
7.8CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
24 Jul 2026Last modified by NVD

Description

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/OSGeo/gdal/issues/14594 Issue TrackingMitigationVendor Advisory
https://github.com/OSGeo/gdal/issues/14594 Issue TrackingMitigationVendor Advisory

Track CVE-2026-49014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-17545Osgeo gdal double free vulnerabilityGDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.EPSS 2.6%8.8CVE-2019-17546Libtiff integer overflow vulnerabilitytif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-ba…EPSS 3.4%7.8CVE-2019-25050Osgeo gdal out-of-bounds write vulnerabilitynetCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_clea…EPSS 0.35%5.5CVE-2025-29480Osgeo gdal classic buffer overflow vulnerabilityBuffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE…EPSS 0.23%5.5CVE-2021-45943Osgeo gdal out-of-bounds write vulnerabilityGDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and …EPSS 1.5%1.9CVE-2026-8212Osgeo gdal memory buffer overflow vulnerabilityA flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWap…EPSS 0.23%1.9CVE-2026-8213Osgeo gdal memory buffer overflow vulnerabilityA vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDa…EPSS 0.23%1.9CVE-2026-8087Osgeo gdal memory buffer overflow vulnerabilityA security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Perf…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-49014), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.