CVE-2026-8087Medium· 5.3▾ SunlitOSGeo GDAL vulnerable to heap-based buffer overflow
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.13.0RC1 is recommended to address this issue. The patch is named 184f77dbcc74118c062c05e464c88161d3c37b9b. You should upgrade the affected component.
gdal < 3.13.0Upgrade to a patched release:
gdal 3.13.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8212Medium· 5.3OSGeo gdal has a heap-based buffer overflow
CVE-2026-8088Low· 3.3OSGeo GDAL vulnerable to out-of-bounds read
CVE-2026-8213Medium· 5.5A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…
CVE-2026-8084Medium· 5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…
CVE-2026-49014High· 7.4GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
CVE-2026-8086High· 7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…