CVE-2026-8212Medium· 5.3▾ SunlitOSGeo gdal has a heap-based buffer overflow
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch commit sha is 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.
gdal < 3.13.0RC1Upgrade to a patched release:
gdal 3.13.0RC1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8213Medium· 5.5A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…
CVE-2026-8088Low· 3.3OSGeo GDAL vulnerable to out-of-bounds read
CVE-2026-8087Medium· 5.3OSGeo GDAL vulnerable to heap-based buffer overflow
CVE-2026-8084Medium· 5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…
CVE-2026-49014High· 7.4GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
CVE-2026-8086High· 7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…