Out of Bounds Read Vulnerability in HDF5 Library by HDF Group
CVE-2026-26197

5.9MEDIUM

Key Information:

Vendor

Hdfgroup

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-26197?

The HDF5 library vulnerability allows for potential out of bounds reads triggered by file manipulation. It occurs when the size attributes of an array datatype in the HDF5 format are maliciously altered, causing a misalignment between the expected array size, number of elements, and element size. While this vulnerability requires deliberate tampering with the file, it poses a significant risk as attackers could exploit this flaw to access or manipulate memory outside the intended boundaries, compromising the integrity of the application using HDF5 data.

Affected Version(s)

hdf5 < 2.0.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.