THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rcr2-hggw-43wm (critical) — surfio has an out-of-bounds read

[GHSA] GHSA-rcr2-hggw-43wm (critical) — surfio has an out-of-bounds read

medgithub_advisoriesPublished 2026-08-18

GHSA-rcr2-hggw-43wm Severity: critical CVE: CVE-2026-55211

surfio has an out-of-bounds read

### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.

### Patches The bug has been patched in version 0.0.19

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rcr2-hggw-43wm