---
id: CVE-2026-55211
title: Surfio is a library for reading and writing surface files
summary: >-
  Surfio is a library for reading and writing surface files. Prior to 0.0.19,
  surfio does not correctly validate size fields in IRAP files, leading to a
  buffer overflow when untrusted files are parsed. The severity assumes surfio
  is used t…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: equinor
product: surfio
affected:
  - surfio < 0.0.19
patched:
  - surfio 0.0.19
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T16:17:30.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55211'
references:
  - url: >-
      https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa
    label: security-advisories@github.com
  - url: >-
      https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db
    label: security-advisories@github.com
  - url: 'https://github.com/equinor/surfio/pull/86'
    label: security-advisories@github.com
  - url: 'https://github.com/equinor/surfio/releases/tag/0.0.19'
    label: security-advisories@github.com
  - url: 'https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-rcr2-hggw-43wm'
tags:
  - nvd
  - cve.org
  - ghsa
  - pip
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-17T15:17:30.741326Z'
epss: 0.00537
epssPercentile: 0.44218
aliases:
  - GHSA-rcr2-hggw-43wm
ecosystem: pip
ingestedAt: '2026-08-18T20:22:15.631Z'
---

## Overview

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55211)

Affected packages:

- `surfio < 0.0.19`

Patched in:

- `surfio 0.0.19`

Source: https://github.com/advisories/GHSA-rcr2-hggw-43wm
