Radare Radare

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Radare product.

RSS Feeds for Radare security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Radare products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Radare Sorted by Most Security Vulnerabilities since 2018

Radare2135 vulnerabilities

Radare2 Extras1 vulnerability

Radare2 Mcp Server1 vulnerability

By the Year

In 2026 there have been 10 vulnerabilities in Radare with an average score of 7.2 out of ten. Last year, in 2025 Radare had 15 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Radare in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.02.




Year Vulnerabilities Average Score
2026 10 7.20
2025 15 4.18
2024 5 6.65
2023 16 8.01
2022 48 6.95
2021 3 7.60
2020 1 9.60
2019 8 7.80
2018 31 6.01

It may take a day or so for new Radare vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Radare Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-8696 May 15, 2026
radare2 6.1.5 UAF in gdbr_pids_list() GDB client core radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.
Radare2
CVE-2026-8695 May 15, 2026
radare2 6.1.5 UAF in gdbr_threads_list() via GDB remote debugging radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list processing.
Radare2
CVE-2026-6942 Apr 23, 2026
radare2-mcp 1.6.0 OS Command Injection via JSONRPC radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.
Radare2 Mcp Server
CVE-2026-6941 Apr 23, 2026
radare2 <6.1.4 PT in project notes handling via malicious .zrp radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
Radare2
CVE-2026-6940 Apr 23, 2026
Radare2 6.1.3 Path Traversal Allowing Local Recursive Deletion radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss.
Radare2
CVE-2026-40517 Apr 22, 2026
radare2 <6.1.4 Command Injection via PDB Parser Print_gvars radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsanitized symbol name interpolation in the flag rename command, which are then executed when a user runs the idp command against the malicious PDB file, enabling arbitrary OS command execution through radare2's shell execution operator.
Radare2
CVE-2026-40527 Apr 17, 2026
radare2 afsvj Command Injection via DWARF Names radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequently runs afsvj, allowing arbitrary shell command execution through the unsanitized parameter interpolation in the pfq command string.
Radare2
CVE-2026-41015 Apr 16, 2026
Command Injection in radare2 < 9236f44 via rabin2 PDB name on UNIX radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
Radare2
CVE-2026-40499 Apr 15, 2026
radare2 <=6.1.3 Cmd-Injection via PDB Section Names radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.
Radare2
CVE-2026-4174 Mar 15, 2026
Radare2 5.9.9 Mach-O Parser DoS via walk_exports_trie (CVE-2026-4174) A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. Upgrading to version 6.1.2 is capable of addressing this issue. The name of the patch is 4371ae84c99c46b48cb21badbbef06b30757aba0. You should upgrade the affected component. The code maintainer states that, "[he] wont consider this bug a DoS".
Radare2
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.