CVE-2026-26200
published 2026-02-19CVE-2026-26200: HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.36%
27.9th percentile
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | — | — |
| hdfgroup | hdf5 | < 1.14.4-2 | 1.14.4-2 |
| hdfgroup | hdf5 | < 1.14.4.2 | 1.14.4.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
vendor_redhat·2026-02-19·CVSS 7.8
CVE-2026-26200 [HIGH] CWE-131 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
A flaw was found in HDF5, a software for managing data. An attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow. This can lead to a denial-of-service
Debian
CVE-2026-26200: hdf5 - HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who c...
vendor_debian·2026·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200: hdf5 - HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who c...
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
Scope: local
bookworm: undetermined
bullseye: undetermined
forky: undetermined
sid: undetermined
trixie: undetermined
VulDB
HDFGroup HDF5 up to 1.14.4-1 heap-based overflow (GHSA-5p2m-j456-9mr2 / Nessus ID 299645)
vuldb·2026-07-01·CVSS 7.8
CVE-2026-26200 [HIGH] HDFGroup HDF5 up to 1.14.4-1 heap-based overflow (GHSA-5p2m-j456-9mr2 / Nessus ID 299645)
A vulnerability was found in HDFGroup HDF5 up to 1.14.4-1 and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-26200. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.
OSV
CVE-2026-26200: HDF5 is software for managing data
osv·2026-02-19·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200: HDF5 is software for managing data
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
No detection rules found.
Exploit-DB
Windows 11 24H2 - Local Privilege Escalation
exploitdb·2026-05-04·CVSS 7.8
CVE-2026-21250 [HIGH] Windows 11 24H2 - Local Privilege Escalation
Windows 11 24H2 - Local Privilege Escalation
---
# Exploit Title: Windows 11 24H2 - Local Privilege Escalation
# Google Dork: inurl:http.sys "Windows 11 24H2" vulnerability | intitle:"HTTP.sys" "CVE-2026-21250" "Elevation of Privilege"
# Date: 2026-02-27
# Exploit Author: London foggy snow
# Vendor Homepage: https://www.microsoft.com/en-us/msrc
# Software Link: https://learn.microsoft.com/en-us/windows/win32/http/http-sys
# Version: Windows 11 24H2 (10.0.26100.7780), Windows 11 25H2 (10.0.26200.7780), Windows Server 2022 23H2 (10.0.25398.2148)
# Tested on: Windows 11 24H2 (x64), Windows Server 2022 23H2 (Server Core x64)
# CVE : CVE-2026-21250
# powershell -> net start http
#define _CRT_SECURE_NO_WARNINGS
#include
#include
#include
#include
#pragma comment(lib, "ws2_32.lib")
#define
Exploit-DB
Windows 11 25H2 - Heap Overflow
exploitdb·2026-04-30·CVSS 7.3
CVE-2026-21248 [HIGH] Windows 11 25H2 - Heap Overflow
Windows 11 25H2 - Heap Overflow
---
# Exploit Title: Windows 11 25H2 - Heap Overflow
Ghost Patch Exploit Framework
# Date: 2026-02-13
# Exploit Author: nu11secur1ty
# Vendor Homepage: https://www.microsoft.com
# Software Link: https://www.microsoft.com/software-download/windows11
# Version: Windows 11 25H2 Build 26200.7830 (Vulnerable)
# Tested on: Windows 11 25H2 Build 26200.7830 (x64)
# CVE : CVE-2026-21248, CVE-2026-21244
# =====================================================================
# DISCLAIMER: This exploit is for authorized security research and
# educational purposes only. Use only on systems you own or have
# explicit permission to test.
# =====================================================================
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
"""
CVE-2026
Bugzilla
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [epel-all]
bugzilla·2026-02-19·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [epel-all]
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [fedora-42]
bugzilla·2026-02-19·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [fedora-42]
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently m
Bugzilla
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
bugzilla·2026-02-19·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
CVE-2026-26200 hdf5: HDF5: Denial of Service due to heap buffer overflow when parsing a crafted h5 file
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
Wiz
CVE-2026-26200 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-26200 [HIGH] CVE-2026-26200 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26200 :
NixOS vulnerability analysis and mitigation
h5
Source : NVD
## 7.8
Score
Published February 19, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
NixOS
Homebrew
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
hdf5
cpe:2.3:a:hdfgroup:hdf5
Sources
Alpine 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19 Severity HIGH No Fix Added at: Feb 21, 2026
Echo Severity HIGH Has Fix Added at: Feb 20, 2026
Homebrew Severity HIGH Has Fix Added at: Feb 24, 2026
Nix Severity HIGH Has Fix Added at: Feb 24, 2026
Windows Severity HIGH Has Fix Added at: Feb 20, 2026
Windows Severity HIGH Has Fix Add
2026-02-19
Published