gdal
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting gdalpage 1 of 1
- CVE-2019-17545CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.0.22019-10-14
vulnerable: 1.10.0 ... 3.0.1 (32 versions)
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
- CVE-2019-25050HIGHCVSS 7.8EG 7.8✓ Fixed in 3.1.02021-07-20
vulnerable: 2.4.2 ... 3.0.4 (8 versions)
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
- CVE-2021-45943MEDIUMCVSS 5.5EG 5.5✓ Fixed in 3.4.12022-01-01
vulnerable: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.4.0
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
- CVE-2025-29480MEDIUMCVSS 5.5EG 5.52025-04-07
Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.
- CVE-2026-8087MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.13.02026-05-07
vulnerable: 1.10.0 ... 3.9.3 (94 versions)
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow.…
- CVE-2026-8088LOWCVSS 3.3EG 3.3✓ Fixed in 3.13.02026-05-07
vulnerable: 1.10.0 ... 3.9.3 (94 versions)
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launch…
- CVE-2026-8212MEDIUMCVSS 5.3EG 5.32026-05-09
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires …
Check whether gdal is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for gdal CVEs against the assets you own.
Start Free Scan →