Heap Use-After-Free Vulnerability in Ghidra by National Security Agency
CVE-2026-100503

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100503?

Ghidra versions up to 12.1.4 have a heap use-after-free vulnerability due to stale INDIRECT effect-op references in the decompiler's Funcdata::opInsertAfter function. This issue allows attackers to craft malicious binaries that exploit the vulnerability during decompilation, leading to crashes in the decompile helper process. This results in service denial for analysts and automated analysis systems, creating significant disruptions if not addressed.

Affected Version(s)

ghidra 0 <= 12.1.4

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.