HDF5 — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
December 16, 2025
Last Seen
August 31, 2026

HDF5 is an open-source data model, file format, and supporting library designed to store and manage large, complex datasets.

Overview

HDF5 is an open-source data model, file format, and supporting library designed to store and manage large, complex datasets. It supports hierarchical structures and chunked storage, enabling efficient I/O for big data; recent memory-safety disclosures in the HDF5 library raise cybersecurity concerns for applications relying on it, as heap corruption, use-after-free, and heap-buffer overflow vulnerabilities could be exploited when processing crafted data.

Related Threat Clusters

Recent Intelligence Reports

  • Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs — Feeds.Feedburner · August 31, 2026
  • Hugging Face Breach: AI Agent Security Lessons — Blog.Gitguardian · July 29, 2026
  • Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident — Huggingface.Co · July 28, 2026
  • CVE-2024-33877 HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. — Api.Msrc.Microsoft · February 21, 2026
  • CVE-2024-32624 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c) resulting in the corruption of the instruction pointer. — Api.Msrc.Microsoft · February 21, 2026
  • CVE-2025-6818 HDF5 H5Ochunk.c H5O__chunk_protect heap — Api.Msrc.Microsoft · December 16, 2025
  • CVE-2025-2913 HDF5 H5FL.c H5FL__blk_gc_list use after free — Api.Msrc.Microsoft · December 16, 2025
  • CVE-2025-44904 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. — Api.Msrc.Microsoft · December 16, 2025

CVSS v3.1 Breakdown