Vulnerability record · CVE-2026-8087 · published 7 May 2026
CVE-2026-8087: Osgeo gdal memory buffer overflow vulnerability
Osgeo · Gdal
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.13.0RC1 is recommended to address this issue. The patch is named 184f77dbcc74118c062c05e464c88161d3c37b9b. You should upgrade the affected component.
Description
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.13.0RC1 is recommended to address this issue. The patch is named 184f77dbcc74118c062c05e464c88161d3c37b9b. You should upgrade the affected component.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/OSGeo/gdal/ | Product |
| https://github.com/OSGeo/gdal/commit/184f77dbcc74118c062c05e464c88161d3c37b9b | Patch |
| https://github.com/OSGeo/gdal/issues/14363 | ExploitIssue TrackingPatchVendor Advisory |
| https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1 | Release Notes |
| https://github.com/biniamf/pocs/tree/main/gdal-gdinqfields_bof | ExploitThird Party Advisory |
| https://vuldb.com/submit/808039 | ExploitThird Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/361840 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/361840/cti | Permissions RequiredVDB Entry |
Track CVE-2026-8087 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-8087), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.