{"id":"CVE-2026-55211","aliases":["GHSA-rcr2-hggw-43wm","PYSEC-2026-3701"],"url":"https://o3.security/vulnerability/CVE-2026-55211","summary":"surfio IRAP header size fields cause out-of-bounds reads","details":"Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.","published":"2026-09-15T15:28:59.014Z","modified":"2026-10-02T08:14:54.185521Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00537,"percentile":0.44012,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"surfio","fixedVersion":"0.0.19"}],"fix":{"url":"https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa","label":"equinor/surfio@1619750"},"references":[{"type":"WEB","url":"https://github.com/equinor/surfio/releases/tag/0.0.19"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55211.json"},{"type":"ADVISORY","url":"https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55211"},{"type":"FIX","url":"https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa"},{"type":"FIX","url":"https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db"},{"type":"FIX","url":"https://github.com/equinor/surfio/pull/86"},{"type":"PACKAGE","url":"https://github.com/equinor/surfio"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T08:14:54.185521Z"}}