criticalCVSS 9.8Vulnerability
CVE-2026-55209
### Impact Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice. ### Patches The bug has been patched starting with version 6.2.9.
Properties
- ghsa_id
- GHSA-pr85-w493-9w3x
- severity
- critical
- summary
- resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
- cvss_score
- 9.8
- cve_id
- CVE-2026-55209
- cvss_vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- is_ghsa_only
- false
- ghsa_published
- 2026-08-18T20:11:04Z
- source_url
- https://github.com/advisories/GHSA-pr85-w493-9w3x
- ghsa_updated
- 2026-08-18T20:11:05Z
Related Entities (7)
HAS_WEAKNESS (4)
→[Weakness]Out-of-bounds Read
→[Weakness]NULL Pointer Dereference
→[Weakness]Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
→[Weakness]Improper Validation of Array Index
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/resdata
AFFECTS (1)
→[Software]pip/resdata
Explore deeper with Ninja Signal's threat intelligence graph