CVE-2026-4738: OSGeo Gdal

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C‎. This issue affects gdal: before 3.11.0.

Affected products

Published 2026-03-24. Last modified 2026-06-17.