{"id":"CVE-2026-49014","aliases":["BIT-gdal-2026-49014","GHSA-wphc-7cm7-8mf7","PYSEC-2026-193"],"url":"https://o3.security/vulnerability/CVE-2026-49014","summary":"GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow","details":"In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.","published":"2026-05-27T01:39:18.976Z","modified":"2026-08-12T03:51:47.944985172Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00102,"percentile":0.01066,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"gdal","fixedVersion":"3.13.1"}],"fix":{"url":"https://github.com/OSGeo/gdal/pull/14598","label":"OSGeo/gdal#14598"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49014.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49014"},{"type":"REPORT","url":"https://github.com/OSGeo/gdal/issues/14594"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/pull/14598"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/commit/f5ebabc1042f3c59b24e7c8ad45dda242d127f09"},{"type":"PACKAGE","url":"https://github.com/OSGeo/gdal"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/blob/v3.13.1/NEWS.md"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/gdal/PYSEC-2026-193.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.944985172Z"}}