{"id":"PYSEC-2026-3701","summary":"surfio has an out-of-bounds read","details":"### Impact\nPrior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.\n\n\n### Patches\nThe bug has been patched in version 0.0.19","aliases":["CVE-2026-55211","GHSA-rcr2-hggw-43wm"],"modified":"2026-08-19T12:45:05.375623949Z","published":"2026-08-19T11:56:28.037745Z","references":[{"type":"WEB","url":"https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm"},{"type":"WEB","url":"https://github.com/equinor/surfio/pull/86"},{"type":"WEB","url":"https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa"},{"type":"PACKAGE","url":"https://github.com/equinor/surfio"},{"type":"WEB","url":"https://github.com/equinor/surfio/releases/tag/0.0.19"},{"type":"PACKAGE","url":"https://pypi.org/project/surfio"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rcr2-hggw-43wm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55211"}],"affected":[{"package":{"name":"surfio","ecosystem":"PyPI","purl":"pkg:pypi/surfio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.19"}]}],"versions":["0.0.0","0.0.10","0.0.11","0.0.12","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.3","0.0.4","0.0.5","0.0.8","0.0.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/surfio/PYSEC-2026-3701.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}