PT-2026-48406 · Ghidra · Ghidra

·

CVE-2026-49495

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v4.0

6.7

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ghidra versions 10.2 through 12.0
Description An uncontrolled resource consumption issue exists in the ExportTrie.parseTrie() function. The software lacks cycle detection when traversing Mach-O binary export tries. A specially crafted Mach-O binary containing circular references in the export trie can lead to unbounded queue growth and exponential string concatenation. This process triggers an OutOfMemoryError, which crashes the Java Virtual Machine (JVM) and results in the loss of all unsaved work.
Recommendations Update to version 12.1.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49495
GHSA-WM33-9F68-3VJG

Affected Products

Ghidra