CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-26199

unknowncovered by 2 sourcesfirst seen 2026-07-14
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If H5Iget_name is invoked on a group id with 0 for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if H5Iget_name is invoked in a way where size can be forced to zero, and there is important data before the name buffer.

CSIRTS triage

What
A buffer underflow issue in certain HDF5 functions has been identified.
Who is affected
No specific deployments or versions are mentioned.
Urgency
The urgency is unclear as the severity is listed as unknown.
Action
No specific action is provided.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-26199

Get an email if CVE-2026-26199 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-26199

CVE.org record

Embed the live status

CVE-2026-26199 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-26199 status](https://www.csirts.com/badge/CVE-2026-26199)](https://www.csirts.com/cve/CVE-2026-26199)