Out-of-memory Vulnerability in Ghidra by National Security Agency
CVE-2026-52753
6.7MEDIUM
What is CVE-2026-52753?
Ghidra prior to version 12.0.3 is susceptible to an out-of-memory vulnerability within the rust_demangle function. This flaw arises due to the allocation of unbounded output buffers without strict size limitations. Malicious actors can exploit this vulnerability by crafting specially crafted Rust symbol names within binaries, which triggers exponential memory allocation and leads to process crashes during binary analysis. Mitigating this issue is crucial to maintain stable functionality and security during analysis operations.
Affected Version(s)
ghidra 0 < 12.0.3
ghidra 12.0.3
