CVE-2026-86095
Last modified
CVE-2026-86095 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unidata | netcdf-c | <= 4.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-86095?
How severe is CVE-2026-86095?
How do I fix CVE-2026-86095?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86073n8n is an open source workflow automation platform. Prior to…5.9
- CVE-2026-86074n8n is an open source workflow automation platform. Prior to…5.9
- CVE-2026-8608The Event Monster – Event Management, Events Calendar, Ticke…5.3
- CVE-2026-8609An unauthenticated attacker can repeatedly call Grafana's OA…7.5
- CVE-2026-86090ntopng before 6.7.260717 fails to perform authorization chec…7.1
- CVE-2026-86091ntopng before 6.7.260717 fails to check user privileges in t…7.1
- CVE-2026-86096PX4 Autopilot through 1.17.0 contains a use-after-free vulne…5.9
- CVE-2026-86097PX4 Autopilot through 1.17.0 contains a null pointer derefer…6.5
- CVE-2026-86098ntop nDPI versions before 6.0 contain a heap buffer overflow…7.4
- CVE-2026-8610The TypeSquare Webfonts for ConoHa plugin for WordPress is v…4.3
- CVE-2026-86100Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate r…6.4
- CVE-2026-8611The Klamra Paycal for Aspaclaria plugin for WordPress is vul…4.3
Are you affected by CVE-2026-86095?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
