HDF5
143 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for HDF5, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
HDF5 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 12 |
| 2025-04 | 0 |
| 2025-05 | 2 |
| 2025-06 | 10 |
| 2025-07 | 3 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 5 |
| 2026-08 | 6 |
| 2026-09 | 1 |
Severity
How the 143 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical19
- High48
- Medium51
- Low18
Latest CVEs
The 15 most recently published vulnerabilities affecting HDF5.
- CVE-2026-92627Heap Use-After-Free in H5T__conv_f_f—
- CVE-2026-19028HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read—
- CVE-2026-19027HDF5 out-of-bounds heap read in N-Bit filter decompression—
- CVE-2026-19026Nbit filter NULL/short parameter-array dereference—
- CVE-2026-19025HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open—
- CVE-2026-19024HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message—
- CVE-2026-19023HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets—
- CVE-2026-17574NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag5.5
- CVE-2026-17573Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field5.5
- CVE-2026-17572HDF5 SOHM List Index Heap Buffer Overflow5.5
- CVE-2026-26199Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero6.5
- CVE-2026-26197Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c7.5
- CVE-2026-29043HDF5 H5T__ref_mem_setnull Heap Buffer Overflow5.5
- CVE-2026-34734HDF5: H5T__conv_struct Use After Free7.8
- CVE-2026-26200HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow7.8
Product grouping is registry-driven, with AI assist and human review. How it works