CVE-2026-100503 MEDIUM

CVE-2026-100503: Ghidra through 12.1.4 Heap Use-After-Free in Decompiler

Vendor Nationalsecurityagency
Product ghidra
Weakness CWE-416
Published September 26, 2026
Last update September 26, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.

Key dates

02Disclosure timeline

September 26, 2026 CVE published