{"id":"CVE-2026-100505","published":"2026-09-26T01:17:00.200","lastModified":"2026-09-28T21:17:11.997","description":"Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious binaries containing strings or constant byte stores that end in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output.","cvssScore":4.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","cwes":["CWE-125"],"vendors":[],"products":[],"references":[{"url":"https://github.com/NationalSecurityAgency/ghidra","tags":[]},{"url":"https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc/Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc#L324-L410","tags":[]},{"url":"https://github.com/NationalSecurityAgency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","tags":[]},{"url":"https://www.vulncheck.com/advisories/ghidra-11.2-through-12.1.4-heap-out-of-bounds-read-via-stringmanager","tags":[]}],"exploitRefs":[{"url":"https://github.com/NationalSecurityAgency/ghidra","tags":[]},{"url":"https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc/Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc#L324-L410","tags":[]},{"url":"https://github.com/NationalSecurityAgency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","tags":[]}],"hasPoc":true,"ai":null}