CVE-2026-55211
surfio IRAP header size fields cause out-of-bounds reads
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
| CWE | CWE-125 |
| Vendor | equinor |
| Product | surfio |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for equinor surfio
Be the first to know when new critical vulnerabilities affecting equinor surfio are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Versions
equinor / surfio
< 0.0.19
References
github.com: https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm github.com: https://github.com/equinor/surfio/pull/86 github.com: https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa github.com: https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db github.com: https://github.com/equinor/surfio/releases/tag/0.0.19