Radare
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Radare product.
RSS Feeds for Radare security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Radare products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Radare Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 10 vulnerabilities in Radare with an average score of 7.2 out of ten. Last year, in 2025 Radare had 15 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Radare in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.02.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 10 | 7.20 |
| 2025 | 15 | 4.18 |
| 2024 | 5 | 6.65 |
| 2023 | 16 | 8.01 |
| 2022 | 48 | 6.95 |
| 2021 | 3 | 7.60 |
| 2020 | 1 | 9.60 |
| 2019 | 8 | 7.80 |
| 2018 | 31 | 6.01 |
It may take a day or so for new Radare vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Radare Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-8696 | May 15, 2026 |
radare2 6.1.5 UAF in gdbr_pids_list() GDB client coreradare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list. |
|
| CVE-2026-8695 | May 15, 2026 |
radare2 6.1.5 UAF in gdbr_threads_list() via GDB remote debuggingradare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list processing. |
|
| CVE-2026-6942 | Apr 23, 2026 |
radare2-mcp 1.6.0 OS Command Injection via JSONRPCradare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication. |
|
| CVE-2026-6941 | Apr 23, 2026 |
radare2 <6.1.4 PT in project notes handling via malicious .zrpradare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory. |
|
| CVE-2026-6940 | Apr 23, 2026 |
Radare2 6.1.3 Path Traversal Allowing Local Recursive Deletionradare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss. |
|
| CVE-2026-40517 | Apr 22, 2026 |
radare2 <6.1.4 Command Injection via PDB Parser Print_gvarsradare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsanitized symbol name interpolation in the flag rename command, which are then executed when a user runs the idp command against the malicious PDB file, enabling arbitrary OS command execution through radare2's shell execution operator. |
|
| CVE-2026-40527 | Apr 17, 2026 |
radare2 afsvj Command Injection via DWARF Namesradare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequently runs afsvj, allowing arbitrary shell command execution through the unsanitized parameter interpolation in the pfq command string. |
|
| CVE-2026-41015 | Apr 16, 2026 |
Command Injection in radare2 < 9236f44 via rabin2 PDB name on UNIXradare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3. |
|
| CVE-2026-40499 | Apr 15, 2026 |
radare2 <=6.1.3 Cmd-Injection via PDB Section Namesradare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file. |
|
| CVE-2026-4174 | Mar 15, 2026 |
Radare2 5.9.9 Mach-O Parser DoS via walk_exports_trie (CVE-2026-4174)A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. Upgrading to version 6.1.2 is capable of addressing this issue. The name of the patch is 4371ae84c99c46b48cb21badbbef06b30757aba0. You should upgrade the affected component. The code maintainer states that, "[he] wont consider this bug a DoS". |
|