Known Vulnerabilities for products from Radare
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Radare".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40527 json | radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF b... | Not Provided | 2026-04-17 | 2026-07-14 |
| CVE-2026-40517 json | radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows atta... | Not Provided | 2026-04-22 | 2026-04-27 |
| CVE-2026-40499 json | radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that all... | Not Provided | 2026-04-15 | 2026-05-01 |
| CVE-2026-14789 json | A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the fi... | Not Provided | 2026-07-06 | 2026-07-09 |
| CVE-2026-14788 json | A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r... | Not Provided | 2026-07-06 | 2026-07-09 |
| CVE-2026-14787 json | A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/... | Not Provided | 2026-07-06 | 2026-07-09 |
| CVE-2026-14786 json | A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the fil... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-14761 json | A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/... | Not Provided | 2026-07-05 | 2026-07-06 |
| CVE-2026-14760 json | A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file l... | Not Provided | 2026-07-05 | 2026-07-09 |
| CVE-2026-14759 json | A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classe... | Not Provided | 2026-07-05 | 2026-07-09 |
| CVE-2026-14758 json | A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of t... | Not Provided | 2026-07-05 | 2026-07-09 |
| CVE-2026-14757 json | A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/c... | Not Provided | 2026-07-05 | 2026-07-07 |
| CVE-2026-8696 json | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows... | Not Provided | 2026-05-15 | 2026-05-19 |
| CVE-2026-8695 json | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to tri... | Not Provided | 2026-05-15 | 2026-05-18 |
| CVE-2026-6942 json | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute ... | Not Provided | 2026-04-23 | 2026-06-04 |
| CVE-2026-6941 json | radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or... | Not Provided | 2026-04-23 | 2026-04-27 |
| CVE-2026-6940 json | radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively... | Not Provided | 2026-04-23 | 2026-04-27 |
| CVE-2023-46570 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
| CVE-2023-46569 json | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h. | 9.8 - CRITICAL | 2023-10-28 | 2023-10-31 |
| CVE-2023-27114 json | radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c. | 5.5 - MEDIUM | 2023-03-10 | 2023-10-17 |
Known software with vulnerabilities from Radare
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Radare | Radare2 | 0.10.0 |