A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-189",
"CWE-191"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95958.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95958.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "203055275618058174291036508883334861229",
"length": 2410
},
"id": "CVE-2026-95958-12911818",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
"target": {
"file": "manape/pe.cpp",
"function": "PE::_parse_debug"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"33765826604628019172252730105075572158",
"242282169106424502577452825759073571541",
"138557355680539797163991359873432692572",
"218194145826622466796947992034312621129",
"315245941320929955109838843372879115859",
"148814365983045753294427306535741804815",
"153453898231057875176662143238216327886",
"28389477889770198995002497088097934643",
"255120771665048233034499203674627293045",
"253888992030271172838955565976768160222",
"40781362153507854641988717830886690590",
"211828006810540739679029644645718164526"
],
"threshold": 0.9
},
"id": "CVE-2026-95958-41195879",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
"target": {
"file": "test/pe.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"150449757161595956829257518583453887766",
"125662290668977430382535874030027334110",
"308761722548703640238985629910105470113",
"92459648585419026371569303263495129636",
"45034918381381407639922780957086206540",
"77015362161510766831128573048101445280",
"67671178252367853468889329246535794297",
"185791943797568669122331063453540475369",
"207244230690172199729002233559573962807",
"199037723076827121447654694793760770713",
"248234574721523015469344325956884135143",
"80040833729223203225869634493043603016",
"141787958273525181300845981623028805081",
"82420976192772785010278977889172312444",
"47377795130464541031358161823815430582",
"300259575825249714815522026421950873773",
"335252139424854863914870782180378657112",
"273557316570587449510229194654736060399",
"286765567890889280303015763816942629057",
"188300456168742942535363556431738697014",
"21369718551232094703919255935487936399",
"296033899009597859043752613581903593956"
],
"threshold": 0.9
},
"id": "CVE-2026-95958-a6397436",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
"target": {
"file": "manape/pe.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "56629245485312805135035015992301647811",
"length": 1192
},
"id": "CVE-2026-95958-bf4cee78",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
"target": {
"file": "manape/pe.cpp",
"function": "PE::_parse_relocations"
}
}
]
"2026-09-25T08:21:34Z"