CVE-2025-6816
Last modified
CVE-2025-6816 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hdfgroup | Hdf5 | 1.14.6 |
References
- https://github.com/HDFGroup/hdf5/issues/5571Exploit, Issue Tracking
- https://vuldb.com/?ctiid.314254Permissions Required, VDB Entry
- https://vuldb.com/?id.314254Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.602291Third Party Advisory, VDB Entry
- https://github.com/HDFGroup/hdf5/issues/5571Exploit, Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6816?
How severe is CVE-2025-6816?
How do I fix CVE-2025-6816?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68153Juju is an open source application orchestration engine that…6.5
- CVE-2025-68154systeminformation is a System and OS information library for…8.1
- CVE-2025-68155@vitejs/plugin-rs provides React Server Components (RSC) sup…7.5
- CVE-2025-68156Expr is an expression language and expression evaluation for…7.5
- CVE-2025-68157Webpack is a module bundler. From version 5.49.0 to before 5…3.7
- CVE-2025-68158Authlib is a Python library which builds OAuth and OpenID Co…8.8
- CVE-2025-68160Issue summary: Writing large, newline-free data into a BIO c…4.7
- CVE-2025-68161The Socket Appender in Apache Log4j Core versions 2.0-beta9 …4.8
- CVE-2025-68162In JetBrains TeamCity before 2025.11 maven embedder allowed …2.7
- CVE-2025-68163In JetBrains TeamCity before 2025.11 stored XSS was possible…4.8
- CVE-2025-68164In JetBrains TeamCity before 2025.11 port enumeration was po…2.7
- CVE-2025-68165In JetBrains TeamCity before 2025.11 reflected XSS was possi…6.1
Are you affected by CVE-2025-6816?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
