{"id":"CVE-2026-55209","aliases":["PYSEC-2026-3694"],"url":"https://o3.security/vulnerability/CVE-2026-55209","summary":"resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read","details":"### Impact\nPrior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.\n\n### Patches\nThe bug has been patched starting with version 6.2.9.","published":"2026-08-18T20:11:04Z","modified":"2026-08-19T12:55:43.580455017Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"resdata","fixedVersion":"6.2.9"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/equinor/resdata/security/advisories/GHSA-pr85-w493-9w3x"},{"type":"PACKAGE","url":"https://github.com/equinor/resdata"},{"type":"WEB","url":"https://github.com/equinor/resdata/releases/tag/6.2.9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T12:55:43.580455017Z"}}