{"id":"PYSEC-2026-3694","summary":"resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read","details":"### Impact\nPrior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.\n\n### Patches\nThe bug has been patched starting with version 6.2.9.","aliases":["CVE-2026-55209","GHSA-pr85-w493-9w3x"],"modified":"2026-08-19T12:45:08.693778249Z","published":"2026-08-19T11:56:27.903833Z","references":[{"type":"WEB","url":"https://github.com/equinor/resdata/security/advisories/GHSA-pr85-w493-9w3x"},{"type":"PACKAGE","url":"https://github.com/equinor/resdata"},{"type":"WEB","url":"https://github.com/equinor/resdata/releases/tag/6.2.9"},{"type":"PACKAGE","url":"https://pypi.org/project/resdata"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pr85-w493-9w3x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55209"}],"affected":[{"package":{"name":"resdata","ecosystem":"PyPI","purl":"pkg:pypi/resdata"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.9"}]}],"versions":["3.0.1","4.0.0","4.1.0","4.1.1","4.1.2","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","5.0.0","5.0.0b0","5.0.1","5.0.2","5.0.3","5.1.0","5.1.1","5.1.2","5.1.3","6.0.1","6.1.0","6.2.0","6.2.2","6.2.3","6.2.4","6.2.5","6.2.6","6.2.7","6.2.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/resdata/PYSEC-2026-3694.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}