---
id: CVE-2026-19026
title: >-
  H5Z__filter_nbit in H5Znbit.c in HDF5 prior to 2.3.0 dereferences cd_values[0]
  through cd_values[4] without validating that cd_values is non-NULL or that
  cd_nelmts is at least 5, the fixed size of the filter's header
summary: >-
  H5Z__filter_nbit in H5Znbit.c in HDF5 prior to 2.3.0 dereferences cd_values[0]
  through cd_values[4] without validating that cd_values is non-NULL or that
  cd_nelmts is at least 5, the fixed size of the filter's header. This allows
  attacke…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-476
  - CWE-1284
vendor: The HDF Group
product: HDF5
affected:
  - HDF5 <=2.3.0
published: '2026-08-05'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:19.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19026'
references:
  - url: 'https://github.com/HDFGroup/hdf5/issues/6489'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6492'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/pull/6497'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6489'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-06T14:31:41.789584Z'
cvssSource: cna
epss: 0.0018
epssPercentile: 0.0696
ingestedAt: '2026-10-06T21:20:28.947Z'
---

## Overview

H5Z__filter_nbit in H5Znbit.c in HDF5 prior to 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows attackers to cause a denial of service via a crafted HDF5 file that stores the N-Bit filter pipeline message with zero client-data values, opened and read via H5Dread, e.g. by the h5ls or h5repack tools.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
