CRITICAL 9.8
PYSEC-2026-3701
surfio has an out-of-bounds read
Quick fix
PYSEC-2026-3701 — surfio: upgrade to the fixed version with the command below.
pip install --upgrade 'surfio>=0.0.19' Details
### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
### Patches The bug has been patched in version 0.0.19
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm [WEB]
- https://github.com/equinor/surfio/pull/86 [WEB]
- https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa [WEB]
- https://github.com/equinor/surfio [PACKAGE]
- https://github.com/equinor/surfio/releases/tag/0.0.19 [WEB]
- https://pypi.org/project/surfio [PACKAGE]
- https://github.com/advisories/GHSA-rcr2-hggw-43wm [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-55211 [ADVISORY]