Known Vulnerabilities for Radare2 by Radare
Listed below are 10 of the newest known vulnerabilities associated with "Radare2" by "Radare".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41015 json | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: alt... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-40527 json | radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF b... | Not Provided | 2026-04-17 | 2026-04-20 |
| CVE-2026-40517 json | radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows atta... | Not Provided | 2026-04-22 | 2026-04-23 |
| CVE-2026-40499 json | radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that all... | Not Provided | 2026-04-15 | 2026-04-20 |
| CVE-2026-6942 json | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute ... | Not Provided | 2026-04-23 | 2026-04-29 |
| CVE-2026-6941 json | radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or... | Not Provided | 2026-04-23 | 2026-04-24 |
| CVE-2026-6940 json | radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively... | Not Provided | 2026-04-23 | 2026-04-24 |
| CVE-2026-4174 json | A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/forma... | Not Provided | 2026-03-16 | 2026-03-17 |
| CVE-2023-46570 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
| CVE-2023-46569 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Radare | Radare2 | 4.5.0 | |||
| Application | Radare | Radare2 | 4.0.0 | |||
| Application | Radare | Radare2 | 3.9.0 | |||
| Application | Radare | Radare2 | 3.8.0 | |||
| Application | Radare | Radare2 | 3.7.1 | |||
| Application | Radare | Radare2 | 3.7.0 | |||
| Application | Radare | Radare2 | 3.5.1 | |||
| Application | Radare | Radare2 | 3.5.0 | |||
| Application | Radare | Radare2 | 3.4.1 | |||
| Application | Radare | Radare2 | 3.4.0 | |||
| Application | Radare | Radare2 | 3.3.0 | |||
| Application | Radare | Radare2 | 3.2.1 | |||
| Application | Radare | Radare2 | 3.2.0 | |||
| Application | Radare | Radare2 | 3.1.3 | |||
| Application | Radare | Radare2 | 3.1.2 | |||
| Application | Radare | Radare2 | 3.1.1 | |||
| Application | Radare | Radare2 | 3.1.0 | |||
| Application | Radare | Radare2 | 3.0.1 | |||
| Application | Radare | Radare2 | 3.0.0 | |||
| Application | Radare | Radare2 | 2.9.0 |