{"id":"GHSA-wphc-7cm7-8mf7","summary":"GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow","details":"In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.","aliases":["BIT-gdal-2026-49014","CVE-2026-49014","PYSEC-2026-193"],"modified":"2026-07-01T18:26:13.624993475Z","published":"2026-05-27T03:30:31Z","database_specific":{"cwe_ids":["CWE-121"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-01T18:07:07Z","nvd_published_at":"2026-05-27T02:16:34Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49014"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/issues/14594"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/pull/14598"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/commit/f5ebabc1042f3c59b24e7c8ad45dda242d127f09"},{"type":"PACKAGE","url":"https://github.com/OSGeo/gdal"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/blob/v3.13.1/NEWS.md"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/gdal/PYSEC-2026-193.yaml"}],"affected":[{"package":{"name":"gdal","ecosystem":"PyPI","purl":"pkg:pypi/gdal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"3.13.1"}]}],"versions":["3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.10.0","3.10.1","3.10.2","3.10.3","3.11.0","3.11.1","3.11.2","3.11.3","3.11.4","3.11.5","3.12.0.post1","3.12.1","3.12.2","3.12.3","3.12.4","3.13.0","3.2.0","3.2.1","3.2.2","3.2.2.1","3.2.3","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.4.1","3.4.2","3.4.3","3.5.0","3.5.0.3","3.5.1","3.5.2","3.5.3","3.6.0","3.6.0.1","3.6.1","3.6.2","3.6.3","3.6.4","3.7.0","3.7.1","3.7.1.1","3.7.2","3.7.3","3.8.0","3.8.1","3.8.2","3.8.3","3.8.4","3.8.5","3.9.0","3.9.1","3.9.2","3.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wphc-7cm7-8mf7/GHSA-wphc-7cm7-8mf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}