Radare2
180 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Radare2, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Radare2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 3 |
| 2025-01 | 0 |
| 2025-02 | 2 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 8 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 4 |
| 2025-11 | 2 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 6 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 9 |
| 2026-08 | 0 |
| 2026-09 | 9 |
Severity
How the 180 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical14
- High67
- Medium77
- Low22
Latest CVEs
The 15 most recently published vulnerabilities affecting Radare2.
- CVE-2026-81883radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode3.3
- CVE-2026-81885radare2: Infinite relocation-chain loop causes denial of service in radare2 NE parser5.5
- CVE-2026-81882radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist parser3.3
- CVE-2026-81886radare2: Uncontrolled memory allocation in radare2 dmp64 parser5.5
- CVE-2026-81884radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser2.5
- CVE-2026-81880radare2: Uncontrolled resource consumption in radare2 PEF loader5.5
- CVE-2026-81879radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling5.5
- CVE-2026-81878radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser5.5
- CVE-2026-81881radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser3.3
- CVE-2026-14789radareorg radare2 Memory64ListStream mdmp.c stack-based overflow3.3
- CVE-2026-14788radareorg radare2 cfile.c r_core_bin_load use after free3.3
- CVE-2026-14787radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow3.3
- CVE-2026-14786radareorg radare2 str.c r_str_word_get0set integer overflow3.3
- CVE-2026-14761radareorg radare2 str.c r_str_append integer overflow3.3
- CVE-2026-14760radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free3.3
Product grouping is registry-driven, with AI assist and human review. How it works