THREAT OPS › Threat News › [GHSA] GHSA-rcr2-hggw-43wm (critical) — surfio has an out-of-bounds read
[GHSA] GHSA-rcr2-hggw-43wm (critical) — surfio has an out-of-bounds read
GHSA-rcr2-hggw-43wm Severity: critical CVE: CVE-2026-55211
surfio has an out-of-bounds read
### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
### Patches The bug has been patched in version 0.0.19
MITRE ATT&CK techniques
- Web ServiceT1102
Indicators of compromise
- CVE-2026-55211cve
Original source: https://github.com/advisories/GHSA-rcr2-hggw-43wm