GDAL is a widely used geospatial data abstraction library that provides standardized access to raster and vector imagery across heterogeneous data formats, with a considerable installed base in GIS applications, remote-sensing tools, and server-side processing pipelines. The observed vulnerability profile reflects the complexity of parsing diverse geospatial file formats and the library's role as a foundational component in downstream applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gdal over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49014HIGH In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-siz | May 27, 2026 | 7.8 | 29 | NO | NO |
CVE-2005-3581HIGH GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path | Nov 16, 2005 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gdal.
Media articles that mention a CVE ID that affects a product developed by Gdal — matched by CVE ID, not by vendor name.