criticalCVSS 9.8Vulnerability

CVE-2026-55211

### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service. ### Patches The bug has been patched in version 0.0.19

Properties

ghsa_id
GHSA-rcr2-hggw-43wm
summary
surfio has an out-of-bounds read
severity
critical
cvss_score
9.8
cve_id
CVE-2026-55211
cvss_vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-18T20:12:55Z
source_url
https://github.com/advisories/GHSA-rcr2-hggw-43wm
ghsa_updated
2026-08-18T20:12:56Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/surfio

AFFECTS (1)

[Software]pip/surfio

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55211 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal