CVE-2025-6270: Hdfgroup HDF5

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the file H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Affected products

  • Hdfgroup HDF5: before 2.0.0 (fixed in 2.0.0)

Published 2025-06-19. Last modified 2026-06-17.