cvedb.io
CVE-2026-49014
HIGH · CVSS 7.4
EPSS exploitation probability: 0%
Published 2026-05-27T02:16:34.180 · Last modified 2026-06-17T10:55:27.107

Summary

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

Affected products

osgeo — gdal

Does this affect you?

Add your gear to cvedb and we'll alert you only when osgeo ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.