Uncontrolled Resource Consumption in Ghidra by NSA
CVE-2026-54389

6.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-54389?

An uncontrolled resource consumption vulnerability exists within the PDB parser in Ghidra prior to version 12.1.3. Attackers can exploit this flaw by supplying a specially crafted PDB file with oversized parameters, which leads to uncontrolled heap growth. This occurs due to the AbstractPdb deserialization routine processing the oversized parameters into an unbounded list, ultimately causing an OutOfMemoryError that bypasses standard exception handling, thereby crashing the Ghidra application.

Affected Version(s)

ghidra 0

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kwenma (@nyst)
.