Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Asif Nadaf

#54281of 57,428
4.4Total CVSS
Vulnerabilities · 1
PT-2026-99145
4.4
2026-09-26
Ghidra · Ghidra · CVE-2026-100505
**Name of the Vulnerable Software and Affected Versions** Ghidra versions 11.2 through 12.1.4 **Description** A heap out-of-bounds read occurs in the `StringManager::getCodepoint()` function when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating the remaining buffer length. An attacker can use malicious binaries containing constant byte stores that end in multi-byte lead units to trigger this issue, resulting in a decompiler crash or the leakage of adjacent heap memory into the decompiled output. **Recommendations** Update Ghidra to a version later than 12.1.4.