PatchSiren

HDFGroup CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM HDFGroup CVE published 2026-07-20

CVE-2026-26199

The HDF5 library is vulnerable to an underflow issue when invoking `H5Iget_name` with a group id and a size parameter of 0. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity. Users of the HDF5 library should be aware of this vulnerabilit [truncated]

MEDIUM HDFGroup CVE published 2026-07-20

CVE-2026-26197

The CVE record describes a vulnerability in HDF5, a high-performance library and file format specification, that can trigger an out of bounds read if a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in agreement. This occurs because the array datatype stores the full size of the datatype separately from the number of elements and the element size [truncated]

HIGH HDFGroup CVE published 2026-04-09

CVE-2026-34734

CVE-2026-34734 is a high-severity vulnerability in HDF5, a data management software. A heap-use-after-free issue was found in the h5dump helper utility, which can be triggered by a malicious h5 file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. The issue was reported on April 9, 2026, and last modified on June 30, 2026. The freed object is referenced in a memmove call from H5T__con [truncated]

HIGH HDFGroup CVE published 2026-02-19

CVE-2026-26200

CVE-2026-26200 is a high-severity vulnerability in HDF5, a data management software. An attacker can exploit this vulnerability to trigger a write-based heap buffer overflow condition, potentially leading to a denial-of-service condition and remote code execution. The vulnerability is fixed in version 1.14.4-2. HDF5 versions prior to 1.14.4-2 are affected. The Common Vulnerability Scoring System (CVSS) sc [truncated]