{"id":"CVE-2026-8088","summary":"OSGeo gdal GDapi.c GDfieldinfo out-of-bounds","details":"A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.13.0RC1 is sufficient to fix this issue. This patch is called a791f70f8eaec540974ec989ca6fb00266b7646c. The affected component should be upgraded.","aliases":["BIT-gdal-2026-8088","GHSA-j3f5-rw74-g4rv","PYSEC-2026-2156"],"modified":"2026-08-12T16:09:21.621631Z","published":"2026-05-07T19:30:11.704Z","related":["CGA-ff8m-98w8-pc4m"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8088.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.13.0dev-4"},{"last_affected":"3.13.0dev-4"}]}]},"references":[{"type":"WEB","url":"https://github.com/OSGeo/gdal/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8088.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8088"},{"type":"ADVISORY","url":"https://vuldb.com/submit/808040"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/361841"},{"type":"REPORT","url":"https://github.com/OSGeo/gdal/issues/14379"},{"type":"REPORT","url":"https://vuldb.com/vuln/361841/cti"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1"},{"type":"EVIDENCE","url":"https://github.com/biniamf/pocs/tree/main/gdal-gdapi-gdfinfo-dimlist-oob-read"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osgeo/gdal","events":[{"introduced":"0"},{"last_affected":"0e3e27c90f57130232d215d783ff49cc332cd950"},{"introduced":"dd0742a208c40fc31293dd94f976d5ce4d01500f"},{"fixed":"a791f70f8eaec540974ec989ca6fb00266b7646c"}],"database_specific":{"cpe":["cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.12.4"},{"introduced":"3.13.0-beta1"},{"last_affected":"3.13.0-beta1"},{"introduced":"3.13.0-beta2"},{"last_affected":"3.13.0-beta2"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["3.13.0-beta1","3.13.0-beta2","v3.12.4RC1","v3.12.4","v3.13.0beta1","v3.12.3RC2","v3.12.3","v3.12.3RC1","v3.12.2RC1","v3.12.2","v3.12.1RC1","v3.12.1","v3.12.0RC1","v3.12.0rc0","v3.12.0beta1","v3.12.0beta0","v3.11.0beta1","v3.8.0RC1","v3.8.0beta1","v3.6.0RC1","v3.5.0RC1","v3.3.0RC1","v3.3.0","v3.3.0beta1","v3.1.0RC1","3.0.3","2.4.4","v2.4.0","v2.3.0beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8088.json","vanir_signatures_modified":"2026-08-12T16:09:21Z","vanir_signatures":[{"target":{"file":"frmts/hdf4/hdf-eos/GDapi.c","function":"GDfieldinfo"},"deprecated":false,"digest":{"length":2619,"function_hash":"285311337474165479603245677509293117146"},"id":"CVE-2026-8088-1d97f454","signature_type":"Function","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c"},{"id":"CVE-2026-8088-d28ee072","signature_type":"Function","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c","function":"SWfinfo"},"deprecated":false,"digest":{"function_hash":"296266930662382277819761698497124010906","length":3042}},{"target":{"file":"frmts/hdf4/hdf-eos/GDapi.c"},"deprecated":false,"digest":{"line_hashes":["290815317125878387779841054426990916384","60171234605230396493797647493825640149","277904157858091376862875188962579496126","7261014713952251831243630176363429660","34826176973746473582423610340012125795"],"threshold":0.9},"id":"CVE-2026-8088-d3cc47c7","signature_type":"Line","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c"},{"source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c"},"deprecated":false,"digest":{"line_hashes":["290815317125878387779841054426990916384","60171234605230396493797647493825640149","277904157858091376862875188962579496126","7261014713952251831243630176363429660","34826176973746473582423610340012125795"],"threshold":0.9},"id":"CVE-2026-8088-f96a7cfe","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}