{"id":"PYSEC-2026-193","details":"In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.","aliases":["BIT-gdal-2026-49014","CVE-2026-49014","GHSA-wphc-7cm7-8mf7"],"modified":"2026-07-13T16:45:11.431168083Z","published":"2026-05-27T02:16:34.180Z","references":[{"type":"REPORT","url":"https://github.com/OSGeo/gdal/issues/14594"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wphc-7cm7-8mf7"}],"affected":[{"package":{"name":"gdal","ecosystem":"PyPI","purl":"pkg:pypi/gdal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"3.13.1"}]}],"versions":["3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.10.0","3.10.1","3.10.2","3.10.3","3.11.0","3.11.1","3.11.2","3.11.3","3.11.4","3.11.5","3.12.0.post1","3.12.1","3.12.2","3.12.3","3.12.4","3.13.0","3.2.0","3.2.1","3.2.2","3.2.2.1","3.2.3","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.4.1","3.4.2","3.4.3","3.5.0","3.5.0.3","3.5.1","3.5.2","3.5.3","3.6.0","3.6.0.1","3.6.1","3.6.2","3.6.3","3.6.4","3.7.0","3.7.1","3.7.1.1","3.7.2","3.7.3","3.8.0","3.8.1","3.8.2","3.8.3","3.8.4","3.8.5","3.9.0","3.9.1","3.9.2","3.9.3"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/gdal/PYSEC-2026-193.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}