CVE-2026-55211
Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
Patches
The bug has been patched in version 0.0.19
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm, https://github.com/equinor/surfio/pull/86, https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa, https://github.com/equinor/surfio, https://github.com/equinor/surfio/releases/tag/0.0.19