The HDF Group maintains HDF5, a widely used scientific data format library and toolkit that, despite a minimal product footprint, sits deep in the data-processing pipelines of research institutions, high-performance computing centers, and enterprise analytics platforms. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating in memory-safety and buffer-management weakness classes including heap-based buffer overflows, out-of-bounds writes and reads, and NULL-pointer dereferences that are inherent to the library's C-based parsing and storage engine. The exposure profile reflects HDF5's role as a foundational component in scientific computing: a single flaw in the library can propagate across diverse downstream applications and environments that depend on it for data interchange. Defenders should inventory products that embed or link HDF5, prioritize patch deployment for this library specifically, and treat disclosed vulnerabilities as potentially high-impact across their research and analytics infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hdfgroup over time
Signals from CVEs in this vendor scope (131 CVEs).
131 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13872CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c. | Jul 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13870CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c. | Jul 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13869CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5O_link_decode in H5Olink.c. | Jul 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13868CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c. | Jul 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13874CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset. | Jul 10, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-13873CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c. | Jul 10, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-13871CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c. | Jul 10, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-34734HIGH HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigge | Apr 9, 2026 | 7.8 | 29 | NO | NO |
CVE-2018-13867CRITICAL An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c. | Jul 10, 2018 | 9.8 | 29 | NO | NO |
CVE-2021-46242HIGH HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry. | Jan 21, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (131 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hdfgroup.
Media articles that mention a CVE ID that affects a product developed by Hdfgroup — matched by CVE ID, not by vendor name.