VYPR
Medium severity5.5NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026

CVE-2026-49495

CVE-2026-49495

Description

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular references in the export trie causes unbounded queue growth and exponential string concatenation, triggering OutOfMemoryError that crashes the entire JVM and loses all unsaved work.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nationalsecurityagency/Ghidrainferred3 versions
    >=10.2,<12.1+ 2 more
    • (no CPE)range: >=10.2,<12.1
    • cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*range: >=10.2,<12.1
    • (no CPE)range: >=10.2, <12.1

Patches

Vulnerability mechanics

References

2

News mentions

1