Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/hdfgroup/hdf5

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.

Join the discussion

CVE-2026-19028 is an integer underflow vulnerability in the HDF5 library up to version 2.3.0. The flaw occurs in the Fletcher32 checksum filter implementation, where the code subtracts 4 bytes from the input buffer size without verifying the buffer length is at least 4 bytes. This can lead to a size_t underflow, causing a denial of service via out-of-bounds reads and application crashes when processing crafted HDF5 files with small Fletcher32-filtered chunks.

Join the discussion

CVE-2026-19027 is an out-of-bounds read vulnerability in The HDF Group's HDF5 library up to version 2.3.0. The flaw exists in specific decompression functions that advance a read index beyond the compressed buffer size, potentially causing heap memory disclosure when processing crafted HDF5 files. This issue can be triggered by reading datasets using functions like H5Dread or tools such as h5ls or h5repack.

Join the discussion

CVE-2026-19026 is a medium severity vulnerability in The HDF Group's HDF5 library up to version 2.3.0. It involves a NULL pointer dereference in the N-Bit filter implementation, which can cause a denial of service when processing crafted HDF5 files with zero client-data values. This affects tools that read such files, like h5ls and h5repack.

Join the discussion

A NULL pointer dereference vulnerability exists in the H5Pget_fill_value function of The HDF Group's HDF5 library before version 2.1.1. This flaw occurs when processing a dataset with a version 1 or 2 fill value message that has the "defined" flag set and a negative size field, which is not normalized properly. This leads to a NULL datatype pointer being passed to H5T_path_find, causing a denial of service.

Join the discussion

A NULL pointer dereference vulnerability exists in HDF5 before version 2.1.1 in the H5Pget_fill_value function. This flaw allows denial of service when processing a dataset with a version 1 or 2 fill value message that has the "defined" flag set and a negative size field, leading to a NULL datatype dereference.

Join the discussion

CVE-2026-19023 is a medium severity vulnerability in The HDF Group's HDF5 software, affecting versions before 2.1.1. It involves an untrusted pointer dereference in the h5dump tool's render_bin_output function. This flaw can cause a denial of service when processing variable-length string datasets with multiple elements in binary dump mode, due to corrupted stride calculations leading to misaligned pointer dereferences.

Join the discussion

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.

Join the discussion

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by H5D__typeinfo_init_phase3 and freed by H5D__typeinfo_term.

Join the discussion
0

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Join the discussion

Showing 1 to 10 of 28 results

Filters:Package: pkg:github/hdfgroup/hdf5
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses