{"id":"CVE-2026-95958","summary":"JusticeRage Manalyze PE Parser pe.cpp _parse_relocations integer underflow","details":"A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue.","modified":"2026-09-25T08:21:34.570590Z","published":"2026-09-23T02:45:14.752Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-189","CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95958.json"},"references":[{"type":"WEB","url":"https://github.com/JusticeRage/Manalyze/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95958"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-95958"},{"type":"ADVISORY","url":"https://vuldb.com/submit/953395"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/408568"},{"type":"REPORT","url":"https://vuldb.com/vuln/408568/cti"},{"type":"FIX","url":"https://github.com/JusticeRage/Manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/justicerage/manalyze","events":[{"introduced":"7db76b061f89d77a526a792b35fcaecbad6bd7b7"},{"fixed":"c372b6bbca9d8c63812be50596fefa4a79c65fd0"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.0.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.0.0"],"database_specific":{"vanir_signatures_modified":"2026-09-25T08:21:34Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0","target":{"file":"manape/pe.cpp","function":"PE::_parse_debug"},"deprecated":false,"digest":{"function_hash":"203055275618058174291036508883334861229","length":2410},"id":"CVE-2026-95958-12911818"},{"source":"https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0","target":{"file":"test/pe.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["33765826604628019172252730105075572158","242282169106424502577452825759073571541","138557355680539797163991359873432692572","218194145826622466796947992034312621129","315245941320929955109838843372879115859","148814365983045753294427306535741804815","153453898231057875176662143238216327886","28389477889770198995002497088097934643","255120771665048233034499203674627293045","253888992030271172838955565976768160222","40781362153507854641988717830886690590","211828006810540739679029644645718164526"]},"id":"CVE-2026-95958-41195879","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0","target":{"file":"manape/pe.cpp"},"deprecated":false,"digest":{"line_hashes":["150449757161595956829257518583453887766","125662290668977430382535874030027334110","308761722548703640238985629910105470113","92459648585419026371569303263495129636","45034918381381407639922780957086206540","77015362161510766831128573048101445280","67671178252367853468889329246535794297","185791943797568669122331063453540475369","207244230690172199729002233559573962807","199037723076827121447654694793760770713","248234574721523015469344325956884135143","80040833729223203225869634493043603016","141787958273525181300845981623028805081","82420976192772785010278977889172312444","47377795130464541031358161823815430582","300259575825249714815522026421950873773","335252139424854863914870782180378657112","273557316570587449510229194654736060399","286765567890889280303015763816942629057","188300456168742942535363556431738697014","21369718551232094703919255935487936399","296033899009597859043752613581903593956"],"threshold":0.9},"id":"CVE-2026-95958-a6397436","signature_type":"Line"},{"source":"https://github.com/justicerage/manalyze/commit/c372b6bbca9d8c63812be50596fefa4a79c65fd0","target":{"file":"manape/pe.cpp","function":"PE::_parse_relocations"},"deprecated":false,"digest":{"function_hash":"56629245485312805135035015992301647811","length":1192},"id":"CVE-2026-95958-bf4cee78","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95958.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}