CVE-2026-8088Low· 3.3▾ SunlitOSGeo GDAL vulnerable to out-of-bounds read
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.13.0RC1 is sufficient to fix this issue. This patch is called a791f70f8eaec540974ec989ca6fb00266b7646c. The affected component should be upgraded.
gdal < 3.13.0Upgrade to a patched release:
gdal 3.13.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8212Medium· 5.3OSGeo gdal has a heap-based buffer overflow
CVE-2026-8084Medium· 5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…
CVE-2026-8087Medium· 5.3OSGeo GDAL vulnerable to heap-based buffer overflow
CVE-2026-8213Medium· 5.5A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…
CVE-2026-49014High· 7.4GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
CVE-2026-8086High· 7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…