{"id":"CVE-2026-100505","summary":"Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager","details":"Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious binaries with constant byte stores ending in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output.","modified":"2026-09-27T08:05:52.014571Z","published":"2026-09-26T00:36:33.247Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100505.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100505.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100505"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ghidra-11.2-through-12.1.4-heap-out-of-bounds-read-via-stringmanager"},{"type":"FIX","url":"https://github.com/NationalSecurityAgency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7"},{"type":"PACKAGE","url":"https://github.com/NationalSecurityAgency/ghidra"},{"type":"ARTICLE","url":"https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc/Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc#L324-L410"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nationalsecurityagency/ghidra","events":[{"introduced":"7e6daf45e1c6a541bddeb8733eb21c4baa354c08"},{"fixed":"8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc"},{"fixed":"e37c57f3d9c29511a1860f0a735df53131d403d7"}],"database_specific":{"extracted_events":[{"introduced":"11.2"},{"fixed":"12.1.4"}],"source":["DESCRIPTION","REFERENCES"]}}],"database_specific":{"vanir_signatures_modified":"2026-09-27T08:05:52Z","vanir_signatures":[{"id":"CVE-2026-100505-0ccb2e23","signature_type":"Function","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc","function":"StringManager::getCodepoint"},"deprecated":false,"digest":{"length":1754,"function_hash":"244985485372101182153287140886856824561"}},{"target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc","function":"StringManager::checkCharacters"},"deprecated":false,"digest":{"function_hash":"124378822496103591949449381715779057593","length":385},"id":"CVE-2026-100505-469997c6","signature_type":"Function","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7"},{"digest":{"line_hashes":["52796199943263868522796570041870210046","101585669608356114393770699951708910482","257081868960267552955125135960762227427","259252695854076204003412135550916224667"],"threshold":0.9},"id":"CVE-2026-100505-73addcfe","signature_type":"Line","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc"},"deprecated":false},{"target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc","function":"StringManager::writeUnicode"},"deprecated":false,"digest":{"function_hash":"117516835803649992395306921234947746497","length":414},"id":"CVE-2026-100505-78db9cbf","signature_type":"Function","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7"},{"digest":{"function_hash":"103063621947276855534055541264458077628","length":388},"id":"CVE-2026-100505-905686bf","signature_type":"Function","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/printlanguage.cc","function":"PrintLanguage::escapeCharacterData"},"deprecated":false},{"id":"CVE-2026-100505-9dc28ab9","signature_type":"Line","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.hh"},"deprecated":false,"digest":{"line_hashes":["263153030446963279386466112140598582094","80348984232650259835540688321788753498","161973130072372584919021740446162372298","192052308389214544942128316874535812756"],"threshold":0.9}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/nationalsecurityagency/ghidra/commit/e37c57f3d9c29511a1860f0a735df53131d403d7","target":{"file":"Ghidra/Features/Decompiler/src/decompile/cpp/stringmanage.cc"},"deprecated":false,"digest":{"line_hashes":["112595566068743791791318673311123680391","25263827761682942860790092312267371467","22524751134854212869159327345787996752","37564045180838198308945995843381682487","213462057574424957886311727138251539138","78054398575550596797341436723713720260","102764709551959140826584691872629381631","5793670747976601081015778624649780299","119312592300278768272679233567012571234","292746168280129533975224605241470343447","331828009574186014543612023683493018951","151257514382000031199359155362523147653","305322978924611979215751020304909329125","333038756070966726065176907308588138676","234889648448808529931847929844082532173","338196062371229713917853998924156346480","131095465350738393235952923551271628108","139331106983031599633813767870758499967","211311964108241623505411574921255507573","133621049575870335748632167424715405726","209904334783674189432666838934834326127","90420294794274490780574261648916407981","202601056587192974476840031795838051144","23854818003300749713717687840862550298","325022517848744799056148393461962531846","226662228214584021102547026937724632978","339581137973090062723031613634834224667","96902105570921374362244803999818365356","66769123677512275301783839469930839757","242103023007146530633254284052561448730","226501445159755738566954571820536468650","51499189288853012027113590812209802190","58511411642408436369733558318869495268"],"threshold":0.9},"id":"CVE-2026-100505-def79925"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100505.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}