Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

radare2 — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in radare2, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for radare2, a reverse engineering framework. The collection covers multiple weakness types associated with this specific product and its historical release versions. Readers can use this resource to track the vendor’s security advisories, analyze the prevalence of a specific weakness class within the product, and review the chronological history of reported flaws.

Vendor: radareorg

CVE ID Title CVSS Severity Published
CVE-2026-81883 radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode CWE-125 3.3 Low 2026-09-22
CVE-2026-81885 radare2: Infinite relocation-chain loop causes denial of service in radare2 NE parser CWE-770 5.5 Medium 2026-09-22
CVE-2026-81882 radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist parser CWE-125 3.3 Low 2026-09-22
CVE-2026-81886 radare2: Uncontrolled memory allocation in radare2 dmp64 parser CWE-770 5.5 Medium 2026-09-22
CVE-2026-81884 radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser CWE-125 2.5 Low 2026-09-22
CVE-2026-81880 radare2: Uncontrolled resource consumption in radare2 PEF loader CWE-400 5.5 Medium 2026-09-22
CVE-2026-81879 radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling CWE-125 5.5 Medium 2026-09-22
CVE-2026-81878 radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser CWE-190 5.5 Medium 2026-09-22
CVE-2026-81881 radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser CWE-125 3.3 Low 2026-09-22
CVE-2026-14789 radareorg radare2 Memory64ListStream mdmp.c stack-based overflow CWE-121 3.3 Low 2026-07-06
CVE-2026-14788 radareorg radare2 cfile.c r_core_bin_load use after free CWE-416 3.3 Low 2026-07-06
CVE-2026-14787 radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow CWE-190 3.3 Low 2026-07-06
CVE-2026-14786 radareorg radare2 str.c r_str_word_get0set integer overflow CWE-190 3.3 Low 2026-07-06
CVE-2026-14761 radareorg radare2 str.c r_str_append integer overflow CWE-190 3.3 Low 2026-07-05
CVE-2026-14760 radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free CWE-416 3.3 Low 2026-07-05
CVE-2026-14759 radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow CWE-122 3.3 Low 2026-07-05
CVE-2026-14758 radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow CWE-190 3.3 Low 2026-07-05
CVE-2026-14757 radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow CWE-190 5.3 Medium 2026-07-05
CVE-2026-8696 radare2 6.1.5 Use-After-Free via gdbr_pids_list() CWE-416 7.5 High 2026-05-15
CVE-2026-8695 radare2 6.1.5 Use-After-Free via gdbr_threads_list() CWE-416 7.5 High 2026-05-15
CVE-2026-6941 radare2 < 6.1.4 Project Notes Path Traversal via Symlink CWE-59 6.6 Medium 2026-04-23
CVE-2026-6940 radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion CWE-22 7.1 High 2026-04-23
CVE-2026-40517 radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names CWE-78 7.8 High 2026-04-22
CVE-2026-40527 radare2 Command Injection via DWARF Parameter Names CWE-78 7.8 High 2026-04-17
CVE-2026-41015 Radare2 安全漏洞 CWE-78 7.4 High 2026-04-16
CVE-2026-40499 radare2 < 6.1.4 Command Injection via PDB Parser print_gvars() CWE-78 7.8 - 2026-04-15
CVE-2026-4174 Radare2 Mach-O File mach0.c walk_exports_trie resource consumption CWE-400 3.3 Low 2026-03-15
CVE-2025-5648 Radare2 radiff2 pal.c r_cons_pal_init memory corruption CWE-119 2.5 Low 2025-06-05
CVE-2025-5647 Radare2 radiff2 cons.c r_cons_context_break_pop memory corruption CWE-119 2.5 Low 2025-06-05
CVE-2025-5646 Radare2 radiff2 pal.c r_cons_rainbow_free memory corruption CWE-119 2.5 Low 2025-06-05

All 47 known CVE vulnerabilities affecting radare2 with full Chinese analysis, references, and POCs where available.