CRITICAL 9.8
PYSEC-2026-3701
surfio has an out-of-bounds read
빠른 조치
PYSEC-2026-3701 — surfio: 아래 명령으로 수정 버전으로 올리세요.
pip install --upgrade 'surfio>=0.0.19' 상세
### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
### Patches The bug has been patched in version 0.0.19
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/equinor/surfio/security/advisories/GHSA-rcr2-hggw-43wm [WEB]
- https://github.com/equinor/surfio/pull/86 [WEB]
- https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa [WEB]
- https://github.com/equinor/surfio [PACKAGE]
- https://github.com/equinor/surfio/releases/tag/0.0.19 [WEB]
- https://pypi.org/project/surfio [PACKAGE]
- https://github.com/advisories/GHSA-rcr2-hggw-43wm [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-55211 [ADVISORY]