VYPR
Medium severity6.5OSV Advisory· Published Jul 20, 2026· Updated Jul 29, 2026

CVE-2026-26199

CVE-2026-26199

Description

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If H5Iget_name is invoked on a group id with 0 for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if H5Iget_name is invoked in a way where size can be forced to zero, and there is important data before the name buffer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Hdfgroup/Hdf5OSV3 versions
    hdf5_1.14.6, hdf5-1.14.6, hdf5_1.14.5, …+ 2 more
    • (no CPE)range: hdf5_1.14.6, hdf5-1.14.6, hdf5_1.14.5, …
    • cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:*range: <2.1.0
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.