What is CVE-2026-19026?
CVE-2026-19026 is a vulnerability in the H5Z__filter_nbit function of HDF5 through version 2.3.0 that dereferences cd_values array without validating it is non-NULL or contains enough elements, potentially allowing attackers to trigger a denial of service via a crafted HDF5 file. Users should update the library or avoid processing untrusted HDF5 files.
Azərbaycanca: CVE-2026-19026, HDF5 kitabxanasında (2.3.0 daxil olmaqla) H5Znbit.c faylındakı H5Z__filter_nbit funksiyasında cd_values massivinin NULL olub-olmaması yoxlanılmadığı üçün baş verir. Təcavüzkar xüsusi hazırlanmış HDF5 faylı vasitəsilə xidmətdən imtina (Denial of Service) vəziyyəti yarada bilər, bu səbəbdən istifadəçilər kitabxananı yeniləməli və ya şübhəli fayllardan qaçınmalıdır.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
Which software component is affected by CVE-2026-19026?
This vulnerability affects the H5Z__filter_nbit function in the H5Znbit.c file of the HDF5 library up to version 2.3.0.
What can an attacker achieve by exploiting this vulnerability?
An attacker can trigger a denial of service condition by using a crafted HDF5 file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.