CVE detail
CVE-2026-8212
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch is called 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 9.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/362429/ctivuldb.com
No excerpt available.
Exploitvuldb.comMay 9, 2026, 11:16 PM - https://vuldb.com/vuln/362429vuldb.com
No excerpt available.
Exploitvuldb.comMay 9, 2026, 11:16 PM - https://vuldb.com/submit/808127vuldb.com
No excerpt available.
Exploitvuldb.comMay 9, 2026, 11:16 PM No excerpt available.
Exploitgithub.comMay 9, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comMay 9, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comMay 9, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comMay 9, 2026, 11:16 PM- https://github.com/OSGeo/gdal/github.com
No excerpt available.
Exploitgithub.comMay 9, 2026, 11:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.90 · max 0 stars
- biniamf/pocsHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- OSGeo/gdalHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-8213CVSS 1.9 · Low
A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid Fil…
- CVE-2025-14956CVSS 1.9 · Low
A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This ma…
- CVE-2020-15196CVSS 8.5 · High
In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has the same shape as the data. T…
- CVE-2013-3245CVSS 6.3 · Medium
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2026-8088CVSS 1.9 · Low
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation c…
- CVE-2026-8087CVSS 1.9 · Low
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the a…