๐Ÿ” CVE Alert

CVE-2026-19023

UNKNOWN 0.0

HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.

CWE CWE-822
Vendor the hdf group
Product hdf5
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for the hdf group hdf5

Be the first to know when new unknown vulnerabilities affecting the hdf group hdf5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The HDF Group / HDF5
<= 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HDFGroup/hdf5/issues/6486