Radare2
This hub aggregates every CVE we track for Radare2, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
171
CVEs tracked
14
Critical
67
High
0
In CISA KEV
Severity distribution
MEDIUM72HIGH67LOW18CRITICAL14
Monthly trend
1
0
3
0
2
1
0
0
8
0
0
0
4
2
0
0
0
0
6
2
0
9
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Radare2.
- CVE-2026-14789radareorg radare2 Memory64ListStream mdmp.c stack-based overflow3.3
- CVE-2026-14788radareorg radare2 cfile.c r_core_bin_load use after free3.3
- CVE-2026-14787radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow3.3
- CVE-2026-14786radareorg radare2 str.c r_str_word_get0set integer overflow3.3
- CVE-2026-14761radareorg radare2 str.c r_str_append integer overflow3.3
- CVE-2026-14760radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free3.3
- CVE-2026-14759radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow3.3
- CVE-2026-14758radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow3.3
- CVE-2026-14757radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow5.3
- CVE-2026-8696radare2 6.1.5 Use-After-Free via gdbr_pids_list()7.5
- CVE-2026-8695radare2 6.1.5 Use-After-Free via gdbr_threads_list()7.5
- CVE-2026-6941radare2 < 6.1.4 Project Notes Path Traversal via Symlink6.6
- CVE-2026-6940radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion7.1
- CVE-2026-40517radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names7.8
- CVE-2026-40527radare2 Command Injection via DWARF Parameter Names7.8
Product normalization is registry-driven with AI assist and human review. How it works