216.73.217.80

CVE-2026-49495

· Published 10/06/2026 14:16 · Modified 11/06/2026 19:49

Labels: CVE-2026-49495 2026-06-10CVE-2026-49495CWE-835[email protected]

Essential information

Published
10/06/2026 14:16
Modified
11/06/2026 19:49
Author
Creator
CVSS
6.7 MEDIUM (v3) 6.7 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular references in the export trie causes unbounded queue growth and exponential string concatenation, triggering OutOfMemoryError that crashes the entire JVM and loses all unsaved work.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nsa / ghidra cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*

References