{"id":"CVE-2026-86095","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86095","summary":"Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length…","details":"Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.","published":"2026-09-04T23:18:03.220","modified":"2026-09-04T23:18:03.220","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Unidata/netcdf-c"},{"type":"WEB","url":"https://github.com/Unidata/netcdf-c/blob/v4.10.1/libhdf5/hdf5attr.c"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/unidata-netcdf-c-through-4.10.1-out-of-bounds-write-via-oversized-hdf5-attribute-name"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T23:18:03.220"}}