{"id":"CVE-2026-55211","title":"Surfio is a library for reading and writing surface files","summary":"Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used t…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-125"],"vendor":"equinor","product":"surfio","affected":["surfio < 0.0.19"],"patched":["surfio 0.0.19"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T16:17:30.147","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55211","references":[{"url":"https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa","label":"security-advisories@github.com"},{"url":"https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db","label":"security-advisories@github.com"},{"url":"https://github.com/equinor/surfio/pull/86","label":"security-advisories@github.com"},{"url":"https://github.com/equinor/surfio/releases/tag/0.0.19","label":"security-advisories@github.com"},{"url":"https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-rcr2-hggw-43wm"}],"tags":["nvd","cve.org","ghsa","pip"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-17T15:17:30.741326Z"},"epss":0.00537,"epssPercentile":0.43994,"aliases":["GHSA-rcr2-hggw-43wm"],"ecosystem":"pip","ingestedAt":"2026-08-18T20:22:15.631Z","slug":"CVE-2026-55211","body":"## Overview\n\nSurfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55211)\n\nAffected packages:\n\n- `surfio < 0.0.19`\n\nPatched in:\n\n- `surfio 0.0.19`\n\nSource: https://github.com/advisories/GHSA-rcr2-hggw-43wm","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}