Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. resdata
  4. ›
  5. CVE-2026-55209

CVE-2026-55209: resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

August 18, 2026

Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.

References

  • github.com/advisories/GHSA-pr85-w493-9w3x
  • github.com/equinor/resdata/releases/tag/6.2.9
  • github.com/equinor/resdata/security/advisories/GHSA-pr85-w493-9w3x
  • nvd.nist.gov/vuln/detail/CVE-2026-55209

Code Behaviors & Features

Detect and mitigate CVE-2026-55209 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.2.9

Fixed versions

  • 6.2.9

Solution

Upgrade to version 6.2.9 or above.

Impact 9.8 CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  • CWE-125: Out-of-bounds Read
  • CWE-129: Improper Validation of Array Index
  • CWE-476: NULL Pointer Dereference

Source file

pypi/resdata/CVE-2026-55209.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 19 Aug 2026 00:17:38 +0000.