HDF5
The HDF Group- Product type
- Other
- Catalog vulnerabilities
- 10
Severity across 10 analyzed records
Verify to analyze this security profile
en
Severity across 10 analyzed records
Verify to analyze this security profile
As of 09/19/2026, within CyStack's analyzed data, HDF5 has 10 security vulnerabilities published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of HDF5 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-92627Heap Use-After-Free in H5T__conv_f_f | Exploitation statusNot known exploited | FixNot confirmed | Published09/16/2026 | SeverityMedium |
CVE-2026-19028HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityMedium |
CVE-2026-19027HDF5 out-of-bounds heap read in N-Bit filter decompression | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityMedium |
CVE-2026-19026Nbit filter NULL/short parameter-array dereference | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityMedium |
CVE-2026-19025HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityMedium |
CVE-2026-19024HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityHigh |
CVE-2026-19023HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets | Exploitation statusPublic exploit | FixNot confirmed | Published08/05/2026 | SeverityMedium |
CVE-2026-17574NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag | Exploitation statusNot known exploited | FixNot confirmed | Published07/27/2026 | SeverityMedium |
CVE-2026-17573Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field | Exploitation statusPublic exploit | FixNot confirmed | Published07/27/2026 | SeverityMedium |
CVE-2026-17572HDF5 SOHM List Index Heap Buffer Overflow | Exploitation statusNot known exploited | FixNot confirmed | Published07/27/2026 | SeverityMedium |