---
id: CVE-2026-19027
title: >-
  The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and
  H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5

  prior to 2.3.0 advance a read index into the compressed chunk buffer without
  bounding it against the…
summary: >-
  The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and
  H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5

  prior to 2.3.0 advance a read index into the compressed chunk buffer without
  bounding it against the…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-125
vendor: The HDF Group
product: HDF5
affected:
  - HDF5 <=2.3.0
published: '2026-08-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:20.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19027'
references:
  - url: 'https://github.com/HDFGroup/hdf5/issues/6489'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6492'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/pull/6497'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6489'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-06T14:29:51.698432Z'
cvssSource: cna
epss: 0.0018
epssPercentile: 0.06958
ingestedAt: '2026-10-06T21:20:28.947Z'
---

## Overview

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5
prior to 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
