๐Ÿ” CVE Alert

CVE-2026-19024

UNKNOWN 0.0

HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5T_path_find with a NULL datatype.

CWE CWE-476
Vendor the hdf group
Product hdf5
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for the hdf group hdf5

Be the first to know when new unknown vulnerabilities affecting the hdf group hdf5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The HDF Group / HDF5
<= 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HDFGroup/hdf5/issues/6487