Ghidra · Ghidra · CVE-2026-100505
**Name of the Vulnerable Software and Affected Versions**
Ghidra versions 11.2 through 12.1.4
**Description**
A heap out-of-bounds read occurs in the `StringManager::getCodepoint()` function when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating the remaining buffer length. An attacker can use malicious binaries containing constant byte stores that end in multi-byte lead units to trigger this issue, resulting in a decompiler crash or the leakage of adjacent heap memory into the decompiled output.
**Recommendations**
Update Ghidra to a version later than 12.1.4.