Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

rizin — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in rizin, with AI-generated Chinese analysis, references, and POCs.

This page documents common weakness types associated with the rizin reverse engineering framework, serving as a central aggregation point for tracking its security posture. It compiles a comprehensive list of known vulnerabilities affecting the rizin product line, covering the full historical timeline from its initial public release through recent updates to ensure no relevant security incidents are omitted. By consulting this resource, users can effectively track vendor advisories to stay informed about newly discovered flaws, gain a deeper understanding of specific weakness classes that impact the framework’s architecture and functionality, and review a product's vulnerability history to assess long-term stability and maintenance practices. The data presented here is intended to assist security researchers, developers, and system administrators in evaluating the risk profile of rizin within their operational environments. This aggregation includes details such as severity ratings, affected versions, and mitigation strategies where available, providing a clear overview of the security landscape surrounding this specific tool. The goal is to provide transparent, factual information that supports informed decision-making regarding the adoption and configuration of rizin in various technical workflows.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-45324 Rizin: Double free in cmd_search.c CWE-415 3.3 Low 2026-05-29
CVE-2026-45613 Rizin: Heap-buffer-overflow in OMF parser CWE-125 3.3 Low 2026-05-29
CVE-2026-22780 Rizin has a heap overflow on mach0_chained_fixups.c CWE-770 4.4 Medium 2026-02-02
CVE-2025-1788 rizinorg rizin utf8.c rz_utf8_encode heap-based overflow CWE-122 5.3 Medium 2025-03-01
CVE-2025-1786 rizinorg rizin pdb.c msf_stream_directory_free buffer overflow CWE-120 5.3 Medium 2025-03-01
CVE-2024-53256 Rizin has a command injection via RzBinInfo bclass due legacy code CWE-78 7.8 High 2024-12-23
CVE-2023-40022 Rizin vulnerable to Integer Overflow in C++ demangler logic CWE-190 7.8 High 2023-08-24
CVE-2021-3674 Rizin 缓冲区错误漏洞 CWE-119 7.8 - 2023-03-24
CVE-2023-27590 Rizin has stack-based buffer overflow when parsing GDB registers profile files CWE-121 7.8 High 2023-03-14
CVE-2022-36039 Out-of-bounds write when parsing DEX files in Rizin CWE-787 7.8 High 2022-09-06
CVE-2022-36044 Rizin Out-of-bounds Write vulnerability in Lua binary plugin CWE-787 7.8 High 2022-09-06
CVE-2022-36043 Rizin Double Free in bobj.c when using qnx binary plugin CWE-415 7.8 High 2022-09-06
CVE-2022-36042 Rizin Out-of-bounds Write vulnerability in dyld cache binary plugin CWE-787 7.8 High 2022-09-06
CVE-2022-36041 Rizin Out-of-bounds Write vulnerability in Mach-O binary plugin CWE-787 7.8 High 2022-09-06
CVE-2022-36040 Rizin Out-of-bounds Write vulnerability in pyc/marshal.c CWE-787 7.8 High 2022-09-06
CVE-2021-4022 Rizin 资源管理错误漏洞 CWE-400 5.5 - 2022-08-25
CVE-2021-43814 Heap-based OOB write when parsing dwarf DIE info in Rizin CWE-787 7.7 High 2021-12-13

All 17 known CVE vulnerabilities affecting rizin with full Chinese analysis, references, and POCs where available.