Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

radare2 — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in radare2, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in radare2, an open-source reverse engineering framework, classified under common weakness types found in binary analysis and manipulation software. It aggregates security issues reported in various databases and advisory sources, covering incidents from the initial public release of the tool through recent updates. By visiting this resource, you can track specific advisories issued by the radare2 development team, understand the patterns and implications associated with these weakness classes, and review the historical vulnerability data for the product. The collection focuses on providing a clear overview of security incidents affecting the framework without promoting any specific vendor or service. Each entry links to detailed information where available, allowing users to assess the impact on their workflows. The scope includes flaws related to memory corruption, input validation, and privilege escalation, among others, which are critical for users relying on radare2 for forensic analysis, malware reverse engineering, or software development. This compilation serves as a neutral reference for security researchers and developers seeking to understand the risk landscape. It does not include proprietary or unverified claims, ensuring the integrity of the data presented. Users can rely on this summary to gauge the overall security posture of radare2 over time and make informed decisions about patching and mitigation strategies. The information is organized to facilitate quick identification of relevant trends and recurring issues within the codebase.

Vendor: radareorg

CVE IDTitleCVSSSeverityPublished
CVE-2026-14789 radareorg radare2 Memory64ListStream mdmp.c stack-based overflow CWE-121 3.3 Low2026-07-06
CVE-2026-14788 radareorg radare2 cfile.c r_core_bin_load use after free CWE-416 3.3 Low2026-07-06
CVE-2026-14787 radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow CWE-190 3.3 Low2026-07-06
CVE-2026-14786 radareorg radare2 str.c r_str_word_get0set integer overflow CWE-190 3.3 Low2026-07-06
CVE-2026-14761 radareorg radare2 str.c r_str_append integer overflow CWE-190 3.3 Low2026-07-05
CVE-2026-14760 radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free CWE-416 3.3 Low2026-07-05
CVE-2026-14759 radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow CWE-122 3.3 Low2026-07-05
CVE-2026-14758 radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow CWE-190 3.3 Low2026-07-05
CVE-2026-14757 radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow CWE-190 5.3 Medium2026-07-05
CVE-2026-8696 radare2 6.1.5 Use-After-Free via gdbr_pids_list() CWE-416 7.5 High2026-05-15
CVE-2026-8695 radare2 6.1.5 Use-After-Free via gdbr_threads_list() CWE-416 7.5 High2026-05-15
CVE-2026-6941 radare2 < 6.1.4 Project Notes Path Traversal via Symlink CWE-59 6.6 Medium2026-04-23
CVE-2026-6940 radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion CWE-22 7.1 High2026-04-23
CVE-2026-40517 radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names CWE-78 7.8 High2026-04-22
CVE-2026-40527 radare2 Command Injection via DWARF Parameter Names CWE-78 7.8 High2026-04-17
CVE-2026-41015 Radare2 安全漏洞 CWE-78 7.4 High2026-04-16
CVE-2026-40499 radare2 < 6.1.4 Command Injection via PDB Parser print_gvars() CWE-78 7.8 -2026-04-15
CVE-2026-4174 Radare2 Mach-O File mach0.c walk_exports_trie resource consumption CWE-400 3.3 Low2026-03-15
CVE-2025-5648 Radare2 radiff2 pal.c r_cons_pal_init memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5647 Radare2 radiff2 cons.c r_cons_context_break_pop memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5646 Radare2 radiff2 pal.c r_cons_rainbow_free memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5645 Radare2 radiff2 pal.c r_cons_pal_init memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5644 Radare2 radiff2 cons.c r_cons_flush use after free CWE-416 2.5 Low2025-06-05
CVE-2025-5643 Radare2 radiff2 cons.c cons_stack_load memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5642 Radare2 radiff2 pal.c r_cons_pal_init memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-5641 Radare2 radiff2 cons.c r_cons_is_breaked memory corruption CWE-119 2.5 Low2025-06-05
CVE-2025-1864 Buffer Overflow and Potential Code Execution in Radare2 CWE-119 7.8 -2025-03-03
CVE-2025-1744 Out-of-bounds Write in radare2 CWE-787 7.8 -2025-02-28
CVE-2025-1378 radare2 rasm2 rasm2.c memory corruption CWE-119 3.3 Low2025-02-17
CVE-2021-32495 Radare2 资源管理错误漏洞 CWE-416 10.0 Critical2023-07-07

All 38 known CVE vulnerabilities affecting radare2 with full Chinese analysis, references, and POCs where available.