๐Ÿ” CVE Alert

CVE-2026-55211

CRITICAL 9.8

surfio IRAP header size fields cause out-of-bounds reads

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.

CWE CWE-125
Vendor equinor
Product surfio
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for equinor surfio

Be the first to know when new critical vulnerabilities affecting equinor surfio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Versions

equinor / surfio
< 0.0.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm github.com: https://github.com/equinor/surfio/pull/86 github.com: https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa github.com: https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db github.com: https://github.com/equinor/surfio/releases/tag/0.0.19