CVE-2026-86095

Source
https://cve.org/CVERecord?id=CVE-2026-86095
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86095.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86095
Downstream
Published
2026-09-04T22:38:46.036Z
Modified
2026-09-06T03:47:21.046224144Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name
Details

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4HDF5inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86095.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/unidata/netcdf-c

Affected ranges

Type
GIT
Repo
https://github.com/unidata/netcdf-c
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.10.1"
        },
        {
            "fixed": "4.10.1"
        }
    ]
}

Affected versions

Other
cdf-5-merge-checkpoint
pre-nczarr-merge

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86095.json"