Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious binaries with constant byte stores ending in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100505.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100505.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "244985485372101182153287140886856824561",
"length": 1754
},
"id": "CVE-2026-100505-0ccb2e23",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
"function": "StringManager::getCodepoint"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "124378822496103591949449381715779057593",
"length": 385
},
"id": "CVE-2026-100505-469997c6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
"function": "StringManager::checkCharacters"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"52796199943263868522796570041870210046",
"101585669608356114393770699951708910482",
"257081868960267552955125135960762227427",
"259252695854076204003412135550916224667"
],
"threshold": 0.9
},
"id": "CVE-2026-100505-73addcfe",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "117516835803649992395306921234947746497",
"length": 414
},
"id": "CVE-2026-100505-78db9cbf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc",
"function": "StringManager::writeUnicode"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "103063621947276855534055541264458077628",
"length": 388
},
"id": "CVE-2026-100505-905686bf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc",
"function": "PrintLanguage::escapeCharacterData"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"263153030446963279386466112140598582094",
"80348984232650259835540688321788753498",
"161973130072372584919021740446162372298",
"192052308389214544942128316874535812756"
],
"threshold": 0.9
},
"id": "CVE-2026-100505-9dc28ab9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.hh"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"112595566068743791791318673311123680391",
"25263827761682942860790092312267371467",
"22524751134854212869159327345787996752",
"37564045180838198308945995843381682487",
"213462057574424957886311727138251539138",
"78054398575550596797341436723713720260",
"102764709551959140826584691872629381631",
"5793670747976601081015778624649780299",
"119312592300278768272679233567012571234",
"292746168280129533975224605241470343447",
"331828009574186014543612023683493018951",
"151257514382000031199359155362523147653",
"305322978924611979215751020304909329125",
"333038756070966726065176907308588138676",
"234889648448808529931847929844082532173",
"338196062371229713917853998924156346480",
"131095465350738393235952923551271628108",
"139331106983031599633813767870758499967",
"211311964108241623505411574921255507573",
"133621049575870335748632167424715405726",
"209904334783674189432666838934834326127",
"90420294794274490780574261648916407981",
"202601056587192974476840031795838051144",
"23854818003300749713717687840862550298",
"325022517848744799056148393461962531846",
"226662228214584021102547026937724632978",
"339581137973090062723031613634834224667",
"96902105570921374362244803999818365356",
"66769123677512275301783839469930839757",
"242103023007146530633254284052561448730",
"226501445159755738566954571820536468650",
"51499189288853012027113590812209802190",
"58511411642408436369733558318869495268"
],
"threshold": 0.9
},
"id": "CVE-2026-100505-def79925",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7",
"target": {
"file": "Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc"
}
}
]
"2026-09-27T08:05:52Z"