CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-19023

unknowncovered by 2 sourcesfirst seen 2026-08-05
Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.

CSIRTS triage

What
Untrusted pointer dereference in h5dump tool when processing variable-length string datasets in binary mode.
Who is affected
Users running h5dump on untrusted HDF5 files with variable-length string datasets.
Urgency
Severity unknown; pointer dereference can cause crash or code execution.
Action
Update HDF5 to patched version or avoid processing untrusted binary datasets with h5dump.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-19023

Get an email if CVE-2026-19023 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-19023

CVE.org record

Embed the live status

CVE-2026-19023 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-19023 status](https://www.csirts.com/badge/CVE-2026-19023)](https://www.csirts.com/cve/CVE-2026-19023)