cbcvebase.

Radare Radare2 vulnerabilities

169 known vulnerabilities affecting radare/radare2.

Total CVEs
169
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH71MEDIUM72LOW10

Vulnerabilities

Page 1 of 9
CVE-2025-1744P3CRITICALCVSS 9.8≤ 5.9.82025-02-28
CVE-2025-1744 [CRITICAL] CWE-787 CVE-2025-1744: Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffe Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.
nvd
CVE-2026-8695P3CRITICALCVSS 9.8≤ 6.1.42026-05-15
CVE-2026-8695 [CRITICAL] CWE-416 CVE-2026-8695: radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allow radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially a
nvd
CVE-2025-1864P3CRITICALCVSS 9.8≤ 5.9.82025-03-03
CVE-2025-1864 [CRITICAL] CWE-119 CVE-2025-1864: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg r Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.
nvd
CVE-2026-40499P3HIGHCVSS 7.8≤ 6.1.42026-04-15
CVE-2026-40499 [HIGH] CWE-78 CVE-2026-40499: radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_ radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed wh
nvd
CVE-2026-40527P3HIGHCVSS 7.8fixed in 6.1.62026-04-17
CVE-2026-40527 [HIGH] CWE-78 CVE-2026-40527: radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequ
nvd
CVE-2026-14789P3HIGHCVSS 7.8≥ 6.1.0, ≤ 6.1.62026-07-06
CVE-2026-14789 [HIGH] CWE-119 CVE-2026-14789: A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknow A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The pa
nvd
CVE-2020-15121P3CRITICALCVSS 9.6fixed in 4.5.02020-07-20
CVE-2020-15121 [CRITICAL] CWE-78 CVE-2020-15121: In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injecti In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.
nvd
CVE-2024-29646P3CRITICALCVSS 9.8v5.8.82024-12-17
CVE-2024-29646 [CRITICAL] CWE-120 CVE-2024-29646: Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary co Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
nvd
CVE-2026-8696P3CRITICALCVSS 9.8≤ 6.1.42026-05-15
CVE-2026-8696 [CRITICAL] CWE-416 CVE-2026-8696: radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GD radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo
nvd
CVE-2026-40517P3HIGHCVSS 7.8fixed in 6.1.42026-04-22
CVE-2026-40517 [HIGH] CWE-78 CVE-2026-40517: radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsanitized symbol name interpolation in the flag rename command
nvd
CVE-2026-14759P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.82026-07-05
CVE-2026-14759 [HIGH] CWE-119 CVE-2026-14759: A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the functio A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been relea
nvd
CVE-2026-41015P3HIGHCVSS 7.4≥ 01ca2f61fa43bd3f4b732447de31b16039d820c0, < 9236f44a28812fe911814e1b3a7bcf1e4de5d3c22026-04-16
CVE-2026-41015 [HIGH] CWE-78 CVE-2026-41015: radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
nvd
CVE-2026-14788P3HIGHCVSS 7.8≥ 6.1.0, ≤ 6.1.62026-07-06
CVE-2026-14788 [HIGH] CWE-119 CVE-2026-14788: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulner A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c
nvd
CVE-2019-14745P3HIGHCVSS 7.8fixed in 3.7.02019-08-07
CVE-2019-14745 [HIGH] CWE-77 CVE-2019-14745: In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
nvd
CVE-2022-0559P3CRITICALCVSS 9.8fixed in 5.6.22022-02-16
CVE-2022-0559 [CRITICAL] CWE-416 CVE-2022-0559: Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
nvd
CVE-2026-6941P3HIGHCVSS 7.8fixed in 6.1.42026-04-23
CVE-2026-6941 [HIGH] CWE-59 CVE-2026-6941: radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that al radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement ch
nvd
CVE-2026-14757P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.82026-07-05
CVE-2026-14757 [HIGH] CWE-189 CVE-2026-14757: A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
nvd
CVE-2026-14787P3HIGHCVSS 7.8≥ 6.1.0, ≤ 6.1.62026-07-06
CVE-2026-14787 [HIGH] CWE-189 CVE-2026-14787: A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handler. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch n
nvd
CVE-2026-14760P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.82026-07-05
CVE-2026-14760 [HIGH] CWE-119 CVE-2026-14760: A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_see A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This
nvd
CVE-2022-0139P3CRITICALCVSS 9.8fixed in 5.6.02022-02-08
CVE-2022-0139 [CRITICAL] CWE-416 CVE-2022-0139: Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
nvd
Radare Radare2 vulnerabilities | cvebase