๐Ÿ” CVE Alert

CVE-2026-96273

MEDIUM 5.5

Ghidra before 12.1.4 Denial of Service via Crafted Database

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, when imported, causes the application to stall and prevents resource cleanup or graceful shutdown.

CWE CWE-460
Vendor nationalsecurityagency
Product ghidra
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for nationalsecurityagency ghidra

Be the first to know when new medium vulnerabilities affecting nationalsecurityagency ghidra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

NationalSecurityAgency / ghidra
0 < 12.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-4w7g-wmg8-fgv5 github.com: https://github.com/NationalSecurityAgency/ghidra/commit/594da048431aab082a9da7c4a965874d07d33310 github.com: https://github.com/NationalSecurityAgency/ghidra/blob/Ghidra_12.1.3_build/Ghidra/Framework/Project/src/main/java/ghidra/framework/data/OptionsDB.java#L358-L366 github.com: https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_12.1.4_build github.com: https://github.com/NationalSecurityAgency/ghidra vulncheck.com: https://www.vulncheck.com/advisories/ghidra-before-12.1.4-denial-of-service-via-crafted-database

Credits

Yuvraj Saxena (0xXA)