Medium severity5.5NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-52759
CVE-2026-52759
Description
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command count value, forcing the parser to allocate excessive heap memory without validating file size, crashing the Ghidra JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*range: <12.1.1
- (no CPE)range: <12.1.1
Patches
Vulnerability mechanics
References
2- github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-v6c3-h9cp-3whfnvdExploitVendor Advisory
- www.vulncheck.com/advisories/ghidra-denial-of-service-via-uncontrolled-memory-allocation-in-mach-o-parsernvdThird Party Advisory
News mentions
1- National Security Agency's Ghidra: 15 Vulnerabilities Disclosed on June 10, 2026Vypr Intelligence · Jun 10, 2026