criticalCVSS 9.8Vulnerability

CVE-2026-55209

### Impact Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice. ### Patches The bug has been patched starting with version 6.2.9.

Properties

ghsa_id
GHSA-pr85-w493-9w3x
severity
critical
summary
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
cvss_score
9.8
cve_id
CVE-2026-55209
cvss_vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-18T20:11:04Z
source_url
https://github.com/advisories/GHSA-pr85-w493-9w3x
ghsa_updated
2026-08-18T20:11:05Z

Related Entities (7)

HAS_WEAKNESS (4)

[Weakness]Out-of-bounds Read
[Weakness]NULL Pointer Dereference
[Weakness]Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
[Weakness]Improper Validation of Array Index

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/resdata

AFFECTS (1)

[Software]pip/resdata

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55209 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal