CVE-2026-100505

Source
https://cve.org/CVERecord?id=CVE-2026-100505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100505
Published
2026-09-26T00:36:33Z
Modified
2026-09-27T08:05:52Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager
Details

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious binaries with constant byte stores ending in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-125"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100505.json"
}
References

Affected packages

Git / github.com/nationalsecurityagency/ghidra

Affected ranges

Type
GIT
Repo
https://github.com/nationalsecurityagency/ghidra
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "11.2"
        },
        {
            "fixed":  "12.1.4"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100505.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "244985485372101182153287140886856824561",
            "length":  1754
        },
        "id":  "CVE-2026-100505-0ccb2e23",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
            "function":  "StringManager::getCodepoint"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "124378822496103591949449381715779057593",
            "length":  385
        },
        "id":  "CVE-2026-100505-469997c6",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
            "function":  "StringManager::checkCharacters"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "52796199943263868522796570041870210046",
                "101585669608356114393770699951708910482",
                "257081868960267552955125135960762227427",
                "259252695854076204003412135550916224667"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-100505-73addcfe",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "117516835803649992395306921234947746497",
            "length":  414
        },
        "id":  "CVE-2026-100505-78db9cbf",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
            "function":  "StringManager::writeUnicode"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "103063621947276855534055541264458077628",
            "length":  388
        },
        "id":  "CVE-2026-100505-905686bf",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc",
            "function":  "PrintLanguage::escapeCharacterData"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "263153030446963279386466112140598582094",
                "80348984232650259835540688321788753498",
                "161973130072372584919021740446162372298",
                "192052308389214544942128316874535812756"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-100505-9dc28ab9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.hh"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "112595566068743791791318673311123680391",
                "25263827761682942860790092312267371467",
                "22524751134854212869159327345787996752",
                "37564045180838198308945995843381682487",
                "213462057574424957886311727138251539138",
                "78054398575550596797341436723713720260",
                "102764709551959140826584691872629381631",
                "5793670747976601081015778624649780299",
                "119312592300278768272679233567012571234",
                "292746168280129533975224605241470343447",
                "331828009574186014543612023683493018951",
                "151257514382000031199359155362523147653",
                "305322978924611979215751020304909329125",
                "333038756070966726065176907308588138676",
                "234889648448808529931847929844082532173",
                "338196062371229713917853998924156346480",
                "131095465350738393235952923551271628108",
                "139331106983031599633813767870758499967",
                "211311964108241623505411574921255507573",
                "133621049575870335748632167424715405726",
                "209904334783674189432666838934834326127",
                "90420294794274490780574261648916407981",
                "202601056587192974476840031795838051144",
                "23854818003300749713717687840862550298",
                "325022517848744799056148393461962531846",
                "226662228214584021102547026937724632978",
                "339581137973090062723031613634834224667",
                "96902105570921374362244803999818365356",
                "66769123677512275301783839469930839757",
                "242103023007146530633254284052561448730",
                "226501445159755738566954571820536468650",
                "51499189288853012027113590812209802190",
                "58511411642408436369733558318869495268"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-100505-def79925",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
        "target":  {
            "file":  "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc"
        }
    }
]
vanir_signatures_modified
"2026-09-27T08:05:52Z"