A vulnerability identified as critical has been detected in HDFGroup HDF5 up to 1.x. Impacted is an unknown function of the component Array datatype. The manipulation of the argument size/nelem/element size leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-26197. The attack is possible to be carried out remotely. No exploit exists.