{"schema_version":1,"title":"GDAL (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in GDAL (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49014, was published on 27 May 2026.","url":"https://junglewise.ai/threats/technologies/gdal","json_url":"https://junglewise.ai/threats/technologies/gdal.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gdal","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":11,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":7},"latest":[{"cve":"CVE-2026-49014","cvss":7.4,"epss":0.0015,"slug":"cve-2026-49014-osgeo-gdal-stack-buffer-overflow-in-netcdf-driver","title":"OSGeo GDAL stack buffer overflow in netCDF driver","severity":"high","exploited":false,"published_at":"2026-05-27T02:16:34.18+00:00","url":"https://junglewise.ai/threats/cve-2026-49014-osgeo-gdal-stack-buffer-overflow-in-netcdf-driver"},{"cve":"CVE-2026-8213","cvss":5.3,"epss":0.0023,"slug":"cve-2026-8213-osgeo-gdal-heap-buffer-overflow-in-grid-file-handler","title":"OSGeo GDAL heap buffer overflow in Grid File Handler","severity":"medium","exploited":false,"published_at":"2026-05-09T23:16:33.29+00:00","url":"https://junglewise.ai/threats/cve-2026-8213-osgeo-gdal-heap-buffer-overflow-in-grid-file-handler"},{"cve":"CVE-2026-8212","cvss":5.3,"epss":0.0023,"slug":"cve-2026-8212-osgeo-gdal-heap-buffer-overflow-in-swsdfldsrch","title":"OSGeo GDAL heap buffer overflow in SWSDfldsrch","severity":"medium","exploited":false,"published_at":"2026-05-09T23:16:33.113+00:00","url":"https://junglewise.ai/threats/cve-2026-8212-osgeo-gdal-heap-buffer-overflow-in-swsdfldsrch"},{"cve":"CVE-2026-8088","cvss":3.3,"epss":0.0022,"slug":"cve-2026-8088-osgeo-gdal-out-of-bounds-read-in-gdfieldinfo","title":"OSGeo GDAL out-of-bounds read in GDfieldinfo","severity":"low","exploited":false,"published_at":"2026-05-07T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2026-8088-osgeo-gdal-out-of-bounds-read-in-gdfieldinfo"},{"cve":"CVE-2026-8087","cvss":5.3,"epss":0.0026,"slug":"cve-2026-8087-osgeo-gdal-heap-buffer-overflow-in-hdf4-eos-driver","title":"OSGeo GDAL heap buffer overflow in HDF4-EOS driver","severity":"medium","exploited":false,"published_at":"2026-05-07T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2026-8087-osgeo-gdal-heap-buffer-overflow-in-hdf4-eos-driver"},{"cve":"CVE-2026-8086","cvss":3.1,"epss":0.0027,"slug":"cve-2026-8086-pysec-2026-2154-a-vulnerability-was-identified-in-osgeo-gdal-up-to","title":"PYSEC-2026-2154 - A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SW","severity":"low","exploited":false,"published_at":"2026-05-07T19:16:03.11+00:00","url":"https://junglewise.ai/threats/cve-2026-8086-pysec-2026-2154-a-vulnerability-was-identified-in-osgeo-gdal-up-to"},{"cve":"CVE-2026-8084","cvss":3.1,"epss":0.0022,"slug":"cve-2026-8084-pysec-2026-2153-a-vulnerability-was-determined-in-osgeo-gdal-up-to","title":"PYSEC-2026-2153 - A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-e","severity":"low","exploited":false,"published_at":"2026-05-07T19:16:02.95+00:00","url":"https://junglewise.ai/threats/cve-2026-8084-pysec-2026-2153-a-vulnerability-was-determined-in-osgeo-gdal-up-to"},{"cve":"CVE-2025-29480","cvss":3.1,"epss":0.0023,"slug":"cve-2025-29480-pysec-2025-117-buffer-overflow-vulnerability-in-gdal-3-10-2","title":"PYSEC-2025-117 - Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release funct","severity":"low","exploited":false,"published_at":"2025-04-07T20:15:20.607+00:00","url":"https://junglewise.ai/threats/cve-2025-29480-pysec-2025-117-buffer-overflow-vulnerability-in-gdal-3-10-2"},{"cve":"CVE-2021-45943","cvss":3.1,"epss":0.0149,"slug":"cve-2021-45943-pysec-2022-43065-gdal-3-3-0-through-3-4-0-has-a-heap-based-buffer","title":"PYSEC-2022-43065 - GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFrom","severity":"low","exploited":false,"published_at":"2022-01-01T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-45943-pysec-2022-43065-gdal-3-3-0-through-3-4-0-has-a-heap-based-buffer"},{"cve":"CVE-2019-25050","cvss":3.1,"epss":0.0035,"slug":"cve-2019-25050-pysec-2021-888-netcdf-in-gdal-2-4-2-through-3-0-4-has-a-stack","title":"PYSEC-2021-888 - netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in","severity":"low","exploited":false,"published_at":"2021-07-20T07:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-25050-pysec-2021-888-netcdf-in-gdal-2-4-2-through-3-0-4-has-a-stack"},{"cve":"CVE-2019-17545","cvss":3.1,"epss":0.0258,"slug":"cve-2019-17545-pysec-2019-241-gdal-through-3-0-1-has-a-pooldestroy-double-free","title":"PYSEC-2019-241 - GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.","severity":"low","exploited":false,"published_at":"2019-10-14T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-17545-pysec-2019-241-gdal-through-3-0-1-has-a-pooldestroy-double-free"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"GDAL (PyPI)","slug":"gdal","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://gdal.org/","repo_url":"https://github.com/OSGeo/gdal","description":"A Python translator library for raster and vector geospatial data formats.","url":"https://junglewise.ai/threats/technologies/gdal"},"most_severe":[{"cve":"CVE-2026-49014","cvss":7.4,"epss":0.0015,"slug":"cve-2026-49014-osgeo-gdal-stack-buffer-overflow-in-netcdf-driver","title":"OSGeo GDAL stack buffer overflow in netCDF driver","severity":"high","exploited":false,"published_at":"2026-05-27T02:16:34.18+00:00","url":"https://junglewise.ai/threats/cve-2026-49014-osgeo-gdal-stack-buffer-overflow-in-netcdf-driver"},{"cve":"CVE-2026-8087","cvss":5.3,"epss":0.0026,"slug":"cve-2026-8087-osgeo-gdal-heap-buffer-overflow-in-hdf4-eos-driver","title":"OSGeo GDAL heap buffer overflow in HDF4-EOS driver","severity":"medium","exploited":false,"published_at":"2026-05-07T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2026-8087-osgeo-gdal-heap-buffer-overflow-in-hdf4-eos-driver"},{"cve":"CVE-2026-8213","cvss":5.3,"epss":0.0023,"slug":"cve-2026-8213-osgeo-gdal-heap-buffer-overflow-in-grid-file-handler","title":"OSGeo GDAL heap buffer overflow in Grid File Handler","severity":"medium","exploited":false,"published_at":"2026-05-09T23:16:33.29+00:00","url":"https://junglewise.ai/threats/cve-2026-8213-osgeo-gdal-heap-buffer-overflow-in-grid-file-handler"},{"cve":"CVE-2026-8212","cvss":5.3,"epss":0.0023,"slug":"cve-2026-8212-osgeo-gdal-heap-buffer-overflow-in-swsdfldsrch","title":"OSGeo GDAL heap buffer overflow in SWSDfldsrch","severity":"medium","exploited":false,"published_at":"2026-05-09T23:16:33.113+00:00","url":"https://junglewise.ai/threats/cve-2026-8212-osgeo-gdal-heap-buffer-overflow-in-swsdfldsrch"},{"cve":"CVE-2026-8088","cvss":3.3,"epss":0.0022,"slug":"cve-2026-8088-osgeo-gdal-out-of-bounds-read-in-gdfieldinfo","title":"OSGeo GDAL out-of-bounds read in GDfieldinfo","severity":"low","exploited":false,"published_at":"2026-05-07T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2026-8088-osgeo-gdal-out-of-bounds-read-in-gdfieldinfo"},{"cve":"CVE-2019-17545","cvss":3.1,"epss":0.0258,"slug":"cve-2019-17545-pysec-2019-241-gdal-through-3-0-1-has-a-pooldestroy-double-free","title":"PYSEC-2019-241 - GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.","severity":"low","exploited":false,"published_at":"2019-10-14T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-17545-pysec-2019-241-gdal-through-3-0-1-has-a-pooldestroy-double-free"},{"cve":"CVE-2021-45943","cvss":3.1,"epss":0.0149,"slug":"cve-2021-45943-pysec-2022-43065-gdal-3-3-0-through-3-4-0-has-a-heap-based-buffer","title":"PYSEC-2022-43065 - GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFrom","severity":"low","exploited":false,"published_at":"2022-01-01T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-45943-pysec-2022-43065-gdal-3-3-0-through-3-4-0-has-a-heap-based-buffer"},{"cve":"CVE-2019-25050","cvss":3.1,"epss":0.0035,"slug":"cve-2019-25050-pysec-2021-888-netcdf-in-gdal-2-4-2-through-3-0-4-has-a-stack","title":"PYSEC-2021-888 - netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in","severity":"low","exploited":false,"published_at":"2021-07-20T07:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-25050-pysec-2021-888-netcdf-in-gdal-2-4-2-through-3-0-4-has-a-stack"},{"cve":"CVE-2026-8086","cvss":3.1,"epss":0.0027,"slug":"cve-2026-8086-pysec-2026-2154-a-vulnerability-was-identified-in-osgeo-gdal-up-to","title":"PYSEC-2026-2154 - A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SW","severity":"low","exploited":false,"published_at":"2026-05-07T19:16:03.11+00:00","url":"https://junglewise.ai/threats/cve-2026-8086-pysec-2026-2154-a-vulnerability-was-identified-in-osgeo-gdal-up-to"},{"cve":"CVE-2025-29480","cvss":3.1,"epss":0.0023,"slug":"cve-2025-29480-pysec-2025-117-buffer-overflow-vulnerability-in-gdal-3-10-2","title":"PYSEC-2025-117 - Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release funct","severity":"low","exploited":false,"published_at":"2025-04-07T20:15:20.607+00:00","url":"https://junglewise.ai/threats/cve-2025-29480-pysec-2025-117-buffer-overflow-vulnerability-in-gdal-3-10-2"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}