CVE-2026-95958

Source
https://cve.org/CVERecord?id=CVE-2026-95958
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95958.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-95958
Published
2026-09-23T02:45:14Z
Modified
2026-09-25T08:21:34Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
JusticeRage Manalyze PE Parser pe.cpp _parse_relocations integer underflow
Details

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-189",
        "CWE-191"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95958.json"
}
References

Affected packages

Git / github.com/justicerage/manalyze

Affected ranges

Type
GIT
Repo
https://github.com/justicerage/manalyze
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.0.0"
        },
        {
            "last_affected":  "1.0.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95958.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "203055275618058174291036508883334861229",
            "length":  2410
        },
        "id":  "CVE-2026-95958-12911818",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
        "target":  {
            "file":  "manape/pe.cpp",
            "function":  "PE::_parse_debug"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "33765826604628019172252730105075572158",
                "242282169106424502577452825759073571541",
                "138557355680539797163991359873432692572",
                "218194145826622466796947992034312621129",
                "315245941320929955109838843372879115859",
                "148814365983045753294427306535741804815",
                "153453898231057875176662143238216327886",
                "28389477889770198995002497088097934643",
                "255120771665048233034499203674627293045",
                "253888992030271172838955565976768160222",
                "40781362153507854641988717830886690590",
                "211828006810540739679029644645718164526"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-95958-41195879",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
        "target":  {
            "file":  "test/pe.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "150449757161595956829257518583453887766",
                "125662290668977430382535874030027334110",
                "308761722548703640238985629910105470113",
                "92459648585419026371569303263495129636",
                "45034918381381407639922780957086206540",
                "77015362161510766831128573048101445280",
                "67671178252367853468889329246535794297",
                "185791943797568669122331063453540475369",
                "207244230690172199729002233559573962807",
                "199037723076827121447654694793760770713",
                "248234574721523015469344325956884135143",
                "80040833729223203225869634493043603016",
                "141787958273525181300845981623028805081",
                "82420976192772785010278977889172312444",
                "47377795130464541031358161823815430582",
                "300259575825249714815522026421950873773",
                "335252139424854863914870782180378657112",
                "273557316570587449510229194654736060399",
                "286765567890889280303015763816942629057",
                "188300456168742942535363556431738697014",
                "21369718551232094703919255935487936399",
                "296033899009597859043752613581903593956"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-95958-a6397436",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
        "target":  {
            "file":  "manape/pe.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "56629245485312805135035015992301647811",
            "length":  1192
        },
        "id":  "CVE-2026-95958-bf4cee78",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0",
        "target":  {
            "file":  "manape/pe.cpp",
            "function":  "PE::_parse_relocations"
        }
    }
]
vanir_signatures_modified
"2026-09-25T08:21:34Z"