CVE Tools

Radare2

180 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Radare2, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Radare2 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Radare2 CVEs per month
MonthCVEs
2024-101
2024-110
2024-123
2025-010
2025-022
2025-031
2025-040
2025-050
2025-068
2025-070
2025-080
2025-090
2025-104
2025-112
2025-120
2026-010
2026-020
2026-030
2026-046
2026-052
2026-060
2026-079
2026-080
2026-099

Severity

How the 180 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical148%
  • High6737%
  • Medium7743%
  • Low2212%

Latest CVEs

The 15 most recently published vulnerabilities affecting Radare2.

  1. CVE-2026-81883radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode3.3
  2. CVE-2026-81885radare2: Infinite relocation-chain loop causes denial of service in radare2 NE parser5.5
  3. CVE-2026-81882radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist parser3.3
  4. CVE-2026-81886radare2: Uncontrolled memory allocation in radare2 dmp64 parser5.5
  5. CVE-2026-81884radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser2.5
  6. CVE-2026-81880radare2: Uncontrolled resource consumption in radare2 PEF loader5.5
  7. CVE-2026-81879radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling5.5
  8. CVE-2026-81878radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser5.5
  9. CVE-2026-81881radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser3.3
  10. CVE-2026-14789radareorg radare2 Memory64ListStream mdmp.c stack-based overflow3.3
  11. CVE-2026-14788radareorg radare2 cfile.c r_core_bin_load use after free3.3
  12. CVE-2026-14787radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow3.3
  13. CVE-2026-14786radareorg radare2 str.c r_str_word_get0set integer overflow3.3
  14. CVE-2026-14761radareorg radare2 str.c r_str_append integer overflow3.3
  15. CVE-2026-14760radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free3.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store