CVE-2026-17574: Hdfgroup HDF5

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

Affected products

  • Hdfgroup HDF5: before 2.1.1 (fixed in 2.1.1)

Published 2026-07-27. Last modified 2026-08-18.