Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55211

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.

EPSS

Процентиль: 44%
0.00537
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.8
github
около 1 месяца назад

surfio has an out-of-bounds read

EPSS

Процентиль: 44%
0.00537
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125