Critical severity9.8NVD Advisory· Published Aug 18, 2026· Updated Aug 18, 2026
surfio has an out-of-bounds read
CVE-2026-55211
Description
Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
Patches
The bug has been patched in version 0.0.19
Affected products
2Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.