CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-100504: ghidra through 12.1.4 (inclusive), 0 through 12.1.4

CVE-2026-100504. CVSS 3.1 base score 7.0 (HIGH, Vendor/CNA). EPSS 0.00127 (percentile 0.02072), scored 2026-10-06.

Affected technology

ghidra · through 12.1.4 (inclusive)
nsa

ghidra · 0 through 12.1.4
NationalSecurityAgency

Description’s affected range: versions through 12.1.4

Component: Not specified by the source
Function: when

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Passive user interaction

What an attacker can do

Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution. Vendor/CNA’s CVSS 4.0 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-787
CCR priority
28.0 /100 (P4)
CVSS 3.1
7.0 /10 · CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00127 · percentile 0.02087 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100504.html