CRITICAL 9.8 GitHub

CVE-2026-55209

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

### Impact Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice. ### Patches The bug has been patched starting with version 6.2.9.

Affected Products

References

Published: 2026-08-18 · Source: GitHub · Feed updated: 2026-08-18
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-18 via GitHub. Affected: pip/resdata < 6.2.9.

Risk Timeline

CVE Disclosed2026-08-18 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-55211surfio has an out-of-bounds readCRITICAL9.8
CVE-2026-55071MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_packageHIGH8.4
CVE-2026-12243nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through PercentHIGH7.5
CVE-2026-55074Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in putHIGH
CVE-2026-52776compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-maHIGH
CVE-2026-54249Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-sidMEDIUM6.8
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.