Known Vulnerabilities for Radare2 by Radare
Listed below are 10 of the newest known vulnerabilities associated with "Radare2" by "Radare".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41015 json | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: alt... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-40527 json | radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF b... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2026-40499 json | radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that all... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2023-46570 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
| CVE-2023-46569 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
| CVE-2023-27114 json | radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c. | 5.5 - MEDIUM | 2023-03-10 | 2023-10-17 |
| CVE-2023-5686 json | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | 8.8 - HIGH | 2023-10-20 | 2023-11-14 |
| CVE-2023-4322 json | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | 9.8 - CRITICAL | 2023-08-14 | 2023-11-14 |
| CVE-2023-1605 json | Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. | 7.5 - HIGH | 2023-03-23 | 2023-03-27 |
| CVE-2023-0302 json | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare... | 7.8 - HIGH | 2023-01-15 | 2023-01-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Radare | Radare2 | 4.5.0 | |||
| Application | Radare | Radare2 | 4.0.0 | |||
| Application | Radare | Radare2 | 3.9.0 | |||
| Application | Radare | Radare2 | 3.8.0 | |||
| Application | Radare | Radare2 | 3.7.1 | |||
| Application | Radare | Radare2 | 3.7.0 | |||
| Application | Radare | Radare2 | 3.5.1 | |||
| Application | Radare | Radare2 | 3.5.0 | |||
| Application | Radare | Radare2 | 3.4.1 | |||
| Application | Radare | Radare2 | 3.4.0 | |||
| Application | Radare | Radare2 | 3.3.0 | |||
| Application | Radare | Radare2 | 3.2.1 | |||
| Application | Radare | Radare2 | 3.2.0 | |||
| Application | Radare | Radare2 | 3.1.3 | |||
| Application | Radare | Radare2 | 3.1.2 | |||
| Application | Radare | Radare2 | 3.1.1 | |||
| Application | Radare | Radare2 | 3.1.0 | |||
| Application | Radare | Radare2 | 3.0.1 | |||
| Application | Radare | Radare2 | 3.0.0 | |||
| Application | Radare | Radare2 | 2.9.0 |