Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ghidra — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Ghidra, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with the Ghidra software, a reverse engineering and analysis suite developed by the National Security Agency. The collection covers various defect categories, including memory safety issues, logic flaws, and authentication bypasses, spanning the full documented history of the tool. Here, users can track how the product’s security posture has evolved, examine the frequency of specific weakness classes like use-after-free or integer overflow, and review the chronology of disclosed fixes. This resource serves as a technical reference for analysts assessing the risk profile of applications built with or analyzed by Ghidra, allowing them to correlate advisory patterns over time. By examining these aggregated records, stakeholders can identify recurring defect types to inform patch management strategies and development prioritization. The data presented focuses strictly on publicly disclosed issues and their resolutions, providing a factual baseline for security auditing.

Vendor: NSA

CVE ID Title CVSS Severity Published
CVE-2026-100505 Ghidra 9.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager CWE-125 4.4 Medium 2026-09-26
CVE-2026-100504 Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128 CWE-787 7.0 High 2026-09-26
CVE-2026-100503 Ghidra through 12.1.4 Heap Use-After-Free in Decompiler CWE-416 3.3 Low 2026-09-26
CVE-2026-96273 Ghidra before 12.1.4 Denial of Service via Unreleased Lock in OptionsDB CWE-460 5.5 Medium 2026-09-23
CVE-2026-54389 Ghidra < 12.1.3 PDB Parser Uncontrolled Heap Growth DoS via AbstractPdb CWE-770 5.5 Medium 2026-08-20
CVE-2026-18718 Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State CWE-427 7.0 High 2026-08-03
CVE-2026-52759 Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser CWE-789 5.5 Medium 2026-06-10
CVE-2026-52758 Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search CWE-89 8.8 High 2026-06-10
CVE-2026-52757 Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilation CWE-416 4.4 Medium 2026-06-10
CVE-2026-52756 Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server CWE-22 4.8 Medium 2026-06-10
CVE-2026-52755 Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import CWE-22 7.8 High 2026-06-10
CVE-2026-52754 Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule CWE-347 8.8 High 2026-06-10
CVE-2026-52753 Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol CWE-789 5.5 Medium 2026-06-10
CVE-2026-52752 Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names CWE-22 7.8 High 2026-06-10
CVE-2026-52751 Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection CWE-502 8.8 High 2026-06-10
CVE-2026-52750 Ghidra < 12.1- Command Injection via URL Annotation Click CWE-88 7.8 High 2026-06-10
CVE-2026-49498 Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username CWE-89 8.8 High 2026-06-10
CVE-2026-49497 Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution CWE-22 3.3 Low 2026-06-10
CVE-2026-49496 Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation CWE-416 6.1 Medium 2026-06-10
CVE-2026-49495 Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Export Trie Parser CWE-835 5.5 Medium 2026-06-10
CVE-2024-58350 Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order CWE-758 2.9 Low 2026-06-10
CVE-2026-4946 NSA Ghidra Auto-Analysis Annotation Command Execution CWE-78 8.8 High 2026-03-29

All 22 known CVE vulnerabilities affecting Ghidra with full Chinese analysis, references, and POCs where available.