Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-55211

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 15, 2026
Vendor unknown

Description

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.

References