CRITICAL 9.8 GitHub
CVE-2026-55211
surfio has an out-of-bounds read
### Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
### Patches
The bug has been patched in version 0.0.19
Affected Products
- pip/surfio < 0.0.19
References
- https://github.com/advisories/GHSA-rcr2-hggw-43wm
- https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm
- https://github.com/equinor/surfio/pull/86
- https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-18 via GitHub. Affected: pip/surfio < 0.0.19.
Risk Timeline
CVE Disclosed2026-08-18 · -1 days ago
Remediation Resources
Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-55209 | resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Po | CRITICAL | 9.8 |
| CVE-2026-55071 | MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package | HIGH | 8.4 |
| CVE-2026-12243 | nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent | HIGH | 7.5 |
| CVE-2026-55074 | Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put | HIGH | — |
| CVE-2026-52776 | compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-ma | HIGH | — |
| CVE-2026-54249 | Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-sid | MEDIUM | 6.8 |
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.