CVE-2026-49014High· 7.4▾ TwilightGDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.1%
In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.
gdal >= 3.1.0, < 3.13.1Upgrade to a patched release:
gdal 3.13.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8212Medium· 5.3OSGeo gdal has a heap-based buffer overflow
CVE-2026-8088Low· 3.3OSGeo GDAL vulnerable to out-of-bounds read
CVE-2026-8087Medium· 5.3OSGeo GDAL vulnerable to heap-based buffer overflow
CVE-2026-8213Medium· 5.5A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…
CVE-2026-8086High· 7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…
CVE-2026-8084Medium· 5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…