CVE-2026-17573: Hdfgroup HDF5
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
Affected products
- Hdfgroup HDF5: before 2.2.0 (fixed in 2.2.0)
Published 2026-07-27. Last modified 2026-08-18.