๐Ÿ” CVE Alert

CVE-2026-17574

UNKNOWN 0.0

NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

CWE CWE-617 CWE-476
Vendor the hdf group
Product hdf5
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for the hdf group hdf5

Be the first to know when new unknown vulnerabilities affecting the hdf group hdf5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The HDF Group / HDF5
<= 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc