Known Vulnerabilities for Ghidra by Nationalsecurityagency
Listed below are 10 of the newest known vulnerabilities associated with "Ghidra" by "Nationalsecurityagency".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-52759 json | Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attacke... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52758 json | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52757 json | Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52756 json | Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52755 json | Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52754 json | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52753 json | Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output bu... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52752 json | Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry name... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52751 json | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that al... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52750 json | Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharact... | Not Provided | 2026-06-10 | 2026-06-10 |