Critical severity9.8NVD Advisory· Published Sep 15, 2026· Updated Sep 30, 2026
CVE-2026-55211
CVE-2026-55211
Description
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
surfioPyPI | < 0.0.19 | 0.0.19 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rcr2-hggw-43wmghsaADVISORY
- github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aanvdWEB
- github.com/equinor/surfio/pull/86nvdWEB
- github.com/equinor/surfio/releases/tag/0.0.19nvdWEB
- github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wmnvdWEB
- github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291dbnvd
News mentions
0No linked articles in our index yet.