🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-26199 is a buffer underflow vulnerability in the HDF5 library functions H5Iget_name and H5G_get_name, triggered when a size parameter of zero is passed. This class of memory corruption flaw can potentially be exploited to read out-of-bounds memory or cause unexpected behaviour in applications processing HDF5 data. Microsoft has published this advisory through the MSRC, indicating relevance to Azure services or components that depend on HDF5.

Security Architect’s Take: Identify any Azure-hosted workloads or data pipelines that process HDF5 files — particularly machine learning, scientific computing, or data analytics services — and ensure the underlying HDF5 library is patched to a fixed version. Review whether any Azure managed services flagged by Microsoft require platform-side updates, and monitor MSRC for patch availability.

Original advisory: CVE-2026-26199 Buffer underflow in H5Iget_name /H5G_get_name if size is zero