{"id":"CVE-2026-55211","aliases":["PYSEC-2026-3701"],"url":"https://o3.security/vulnerability/CVE-2026-55211","summary":"surfio has an out-of-bounds read","details":"### Impact\nPrior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.\n\n\n### Patches\nThe bug has been patched in version 0.0.19","published":"2026-08-18T20:12:55Z","modified":"2026-08-19T12:55:34.365580878Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"surfio","fixedVersion":"0.0.19"}],"fix":{"url":"https://github.com/equinor/surfio/pull/86","label":"equinor/surfio#86"},"references":[{"type":"WEB","url":"https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm"},{"type":"WEB","url":"https://github.com/equinor/surfio/pull/86"},{"type":"WEB","url":"https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa"},{"type":"PACKAGE","url":"https://github.com/equinor/surfio"},{"type":"WEB","url":"https://github.com/equinor/surfio/releases/tag/0.0.19"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T12:55:34.365580878Z"}}