{"schema_version":1,"title":"National Security Agency Ghidra vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in National Security Agency Ghidra: 3 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100505, was published on 26 September 2026.","url":"https://junglewise.ai/threats/technologies/ghidra","json_url":"https://junglewise.ai/threats/technologies/ghidra.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ghidra","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":19,"critical":0,"exploited":0,"last_7_days":3,"last_30_days":3,"last_90_days":4,"last_365_days":19},"latest":[{"cve":"CVE-2026-100505","cvss":4.4,"slug":"cve-2026-100505-ghidra-versions-11-2-through-12-1-4-contain-a-heap-out-of-bounds","title":"National Security Agency Ghidra heap out-of-bounds read in StringManager","severity":"medium","exploited":false,"published_at":"2026-09-26T01:17:00.2+00:00","url":"https://junglewise.ai/threats/cve-2026-100505-ghidra-versions-11-2-through-12-1-4-contain-a-heap-out-of-bounds"},{"cve":"CVE-2026-100504","cvss":7,"slug":"cve-2026-100504-ghidra-versions-through-12-1-4-contain-a-stack-based-out-of","title":"Ghidra stack-based buffer overflow in decompiler leftshift128 function","severity":"high","exploited":false,"published_at":"2026-09-26T01:17:00.043+00:00","url":"https://junglewise.ai/threats/cve-2026-100504-ghidra-versions-through-12-1-4-contain-a-stack-based-out-of"},{"cve":"CVE-2026-96273","cvss":5.5,"epss":0.0012,"slug":"cve-2026-96273-ghidra-before-12-1-4-fails-to-validate-the-type-col-byte-in","title":"National Security Agency Ghidra improper input validation in OptionsDB","severity":"medium","exploited":false,"published_at":"2026-09-23T01:16:32.79+00:00","url":"https://junglewise.ai/threats/cve-2026-96273-ghidra-before-12-1-4-fails-to-validate-the-type-col-byte-in"},{"cve":"CVE-2026-54389","cvss":5.5,"epss":0.0018,"slug":"cve-2026-54389-national-security-agency-ghidra-uncontrolled-resource-consumption","title":"National Security Agency Ghidra uncontrolled resource consumption in PDB parser","severity":"medium","exploited":false,"published_at":"2026-08-20T22:17:21.117+00:00","url":"https://junglewise.ai/threats/cve-2026-54389-national-security-agency-ghidra-uncontrolled-resource-consumption"},{"cve":"CVE-2026-52759","cvss":5.5,"slug":"cve-2026-52759-nsa-ghidra-denial-of-service-in-mach-o-binary-parser","title":"NSA Ghidra denial of service in Mach-O binary parser","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:36.307+00:00","url":"https://junglewise.ai/threats/cve-2026-52759-nsa-ghidra-denial-of-service-in-mach-o-binary-parser"},{"cve":"CVE-2026-52758","cvss":8.8,"slug":"cve-2026-52758-nsa-ghidra-sql-injection-in-bsim-search-filters","title":"NSA Ghidra SQL injection in BSim search filters","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:36.17+00:00","url":"https://junglewise.ai/threats/cve-2026-52758-nsa-ghidra-sql-injection-in-bsim-search-filters"},{"cve":"CVE-2026-52757","cvss":4.4,"slug":"cve-2026-52757-nsa-ghidra-heap-use-after-free-in-decompiler-highvariable-merge","title":"NSA Ghidra heap use-after-free in decompiler HighVariable::merge","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:36.027+00:00","url":"https://junglewise.ai/threats/cve-2026-52757-nsa-ghidra-heap-use-after-free-in-decompiler-highvariable-merge"},{"cve":"CVE-2026-52756","cvss":4.8,"slug":"cve-2026-52756-nsa-ghidra-path-traversal-in-debugger-isfserver","title":"NSA Ghidra path traversal in Debugger IsfServer","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:35.88+00:00","url":"https://junglewise.ai/threats/cve-2026-52756-nsa-ghidra-path-traversal-in-debugger-isfserver"},{"cve":"CVE-2026-52755","cvss":7.8,"slug":"cve-2026-52755-nsa-ghidra-path-traversal-in-theme-import","title":"NSA Ghidra path traversal in theme import","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.747+00:00","url":"https://junglewise.ai/threats/cve-2026-52755-nsa-ghidra-path-traversal-in-theme-import"},{"cve":"CVE-2026-52753","cvss":5.5,"slug":"cve-2026-52753-nsa-ghidra-out-of-memory-vulnerability-in-rust-demangler","title":"NSA Ghidra out-of-memory vulnerability in Rust demangler","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:35.47+00:00","url":"https://junglewise.ai/threats/cve-2026-52753-nsa-ghidra-out-of-memory-vulnerability-in-rust-demangler"},{"cve":"CVE-2026-52752","cvss":7.8,"slug":"cve-2026-52752-nsa-ghidra-path-traversal-in-extension-installer","title":"NSA Ghidra path traversal in extension installer","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.337+00:00","url":"https://junglewise.ai/threats/cve-2026-52752-nsa-ghidra-path-traversal-in-extension-installer"},{"cve":"CVE-2026-52751","cvss":8.8,"slug":"cve-2026-52751-nsa-ghidra-unsafe-deserialization-in-shared-project-rmi","title":"NSA Ghidra unsafe deserialization in Shared-Project RMI connection","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.187+00:00","url":"https://junglewise.ai/threats/cve-2026-52751-nsa-ghidra-unsafe-deserialization-in-shared-project-rmi"},{"cve":"CVE-2026-52750","cvss":7.8,"slug":"cve-2026-52750-nsa-ghidra-command-injection-in-url-annotation-handling-on","title":"NSA Ghidra command injection in URL annotation handling on Windows","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.05+00:00","url":"https://junglewise.ai/threats/cve-2026-52750-nsa-ghidra-command-injection-in-url-annotation-handling-on"},{"cve":"CVE-2026-49498","cvss":8.8,"slug":"cve-2026-49498-nsa-ghidra-sql-injection-in-bsim-postgresfunctiondatabase","title":"NSA Ghidra SQL injection in BSim PostgresFunctionDatabase","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:34.777+00:00","url":"https://junglewise.ai/threats/cve-2026-49498-nsa-ghidra-sql-injection-in-bsim-postgresfunctiondatabase"},{"cve":"CVE-2026-49497","cvss":3.3,"slug":"cve-2026-49497-nsa-ghidra-path-traversal-in-samedirdebuginfoprovider","title":"NSA Ghidra path traversal in SameDirDebugInfoProvider","severity":"low","exploited":false,"published_at":"2026-06-10T14:16:34.643+00:00","url":"https://junglewise.ai/threats/cve-2026-49497-nsa-ghidra-path-traversal-in-samedirdebuginfoprovider"},{"cve":"CVE-2026-49496","cvss":6.1,"slug":"cve-2026-49496-nsa-ghidra-heap-use-after-free-in-sleighbuilder","title":"NSA Ghidra heap-use-after-free in SleighBuilder::generatePointerAdd","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:34.497+00:00","url":"https://junglewise.ai/threats/cve-2026-49496-nsa-ghidra-heap-use-after-free-in-sleighbuilder"},{"cve":"CVE-2026-49495","cvss":5.5,"slug":"cve-2026-49495-nsa-ghidra-denial-of-service-in-mach-o-exporttrie-parser","title":"NSA Ghidra denial of service in Mach-O ExportTrie parser","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:34.36+00:00","url":"https://junglewise.ai/threats/cve-2026-49495-nsa-ghidra-denial-of-service-in-mach-o-exporttrie-parser"},{"cve":"CVE-2024-58350","cvss":2.9,"slug":"cve-2024-58350-nsa-ghidra-use-after-free-in-sleigh-backend-shutdown","title":"NSA Ghidra use after free in Sleigh backend shutdown","severity":"low","exploited":false,"published_at":"2026-06-10T14:16:28.893+00:00","url":"https://junglewise.ai/threats/cve-2024-58350-nsa-ghidra-use-after-free-in-sleigh-backend-shutdown"},{"cve":"CVE-2026-4946","cvss":8.8,"epss":0.0077,"slug":"cve-2026-4946-national-security-agency-ghidra-arbitrary-code-execution-via","title":"National Security Agency Ghidra arbitrary code execution via @execute annotation","severity":"high","exploited":false,"published_at":"2026-03-29T20:16:12.723+00:00","url":"https://junglewise.ai/threats/cve-2026-4946-national-security-agency-ghidra-arbitrary-code-execution-via"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":3}],"related":[],"technology":{"hub":true,"name":"National Security Agency Ghidra","slug":"ghidra","vendor":{"name":"National Security Agency","slug":"national-security-agency","url":"https://junglewise.ai/threats/vendors/national-security-agency"},"aliases":[],"category":"software-development-tool","homepage":"https://ghidra-sre.org/","repo_url":"https://github.com/NationalSecurityAgency/ghidra","description":"Ghidra is a software reverse engineering (SRE) framework developed by the National Security Agency (NSA) that includes a suite of full-featured, high-end software analysis tools.","url":"https://junglewise.ai/threats/technologies/ghidra"},"most_severe":[{"cve":"CVE-2026-4946","cvss":8.8,"epss":0.0077,"slug":"cve-2026-4946-national-security-agency-ghidra-arbitrary-code-execution-via","title":"National Security Agency Ghidra arbitrary code execution via @execute annotation","severity":"high","exploited":false,"published_at":"2026-03-29T20:16:12.723+00:00","url":"https://junglewise.ai/threats/cve-2026-4946-national-security-agency-ghidra-arbitrary-code-execution-via"},{"cve":"CVE-2026-52758","cvss":8.8,"slug":"cve-2026-52758-nsa-ghidra-sql-injection-in-bsim-search-filters","title":"NSA Ghidra SQL injection in BSim search filters","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:36.17+00:00","url":"https://junglewise.ai/threats/cve-2026-52758-nsa-ghidra-sql-injection-in-bsim-search-filters"},{"cve":"CVE-2026-52751","cvss":8.8,"slug":"cve-2026-52751-nsa-ghidra-unsafe-deserialization-in-shared-project-rmi","title":"NSA Ghidra unsafe deserialization in Shared-Project RMI connection","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.187+00:00","url":"https://junglewise.ai/threats/cve-2026-52751-nsa-ghidra-unsafe-deserialization-in-shared-project-rmi"},{"cve":"CVE-2026-49498","cvss":8.8,"slug":"cve-2026-49498-nsa-ghidra-sql-injection-in-bsim-postgresfunctiondatabase","title":"NSA Ghidra SQL injection in BSim PostgresFunctionDatabase","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:34.777+00:00","url":"https://junglewise.ai/threats/cve-2026-49498-nsa-ghidra-sql-injection-in-bsim-postgresfunctiondatabase"},{"cve":"CVE-2026-52755","cvss":7.8,"slug":"cve-2026-52755-nsa-ghidra-path-traversal-in-theme-import","title":"NSA Ghidra path traversal in theme import","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.747+00:00","url":"https://junglewise.ai/threats/cve-2026-52755-nsa-ghidra-path-traversal-in-theme-import"},{"cve":"CVE-2026-52752","cvss":7.8,"slug":"cve-2026-52752-nsa-ghidra-path-traversal-in-extension-installer","title":"NSA Ghidra path traversal in extension installer","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.337+00:00","url":"https://junglewise.ai/threats/cve-2026-52752-nsa-ghidra-path-traversal-in-extension-installer"},{"cve":"CVE-2026-52750","cvss":7.8,"slug":"cve-2026-52750-nsa-ghidra-command-injection-in-url-annotation-handling-on","title":"NSA Ghidra command injection in URL annotation handling on Windows","severity":"high","exploited":false,"published_at":"2026-06-10T14:16:35.05+00:00","url":"https://junglewise.ai/threats/cve-2026-52750-nsa-ghidra-command-injection-in-url-annotation-handling-on"},{"cve":"CVE-2026-100504","cvss":7,"slug":"cve-2026-100504-ghidra-versions-through-12-1-4-contain-a-stack-based-out-of","title":"Ghidra stack-based buffer overflow in decompiler leftshift128 function","severity":"high","exploited":false,"published_at":"2026-09-26T01:17:00.043+00:00","url":"https://junglewise.ai/threats/cve-2026-100504-ghidra-versions-through-12-1-4-contain-a-stack-based-out-of"},{"cve":"CVE-2026-49496","cvss":6.1,"slug":"cve-2026-49496-nsa-ghidra-heap-use-after-free-in-sleighbuilder","title":"NSA Ghidra heap-use-after-free in SleighBuilder::generatePointerAdd","severity":"medium","exploited":false,"published_at":"2026-06-10T14:16:34.497+00:00","url":"https://junglewise.ai/threats/cve-2026-49496-nsa-ghidra-heap-use-after-free-in-sleighbuilder"},{"cve":"CVE-2026-54389","cvss":5.5,"epss":0.0018,"slug":"cve-2026-54389-national-security-agency-ghidra-uncontrolled-resource-consumption","title":"National Security Agency Ghidra uncontrolled resource consumption in PDB parser","severity":"medium","exploited":false,"published_at":"2026-08-20T22:17:21.117+00:00","url":"https://junglewise.ai/threats/cve-2026-54389-national-security-agency-ghidra-uncontrolled-resource-consumption"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}