Medium severity5.5NVD Advisory· Published Sep 23, 2026
CVE-2026-96273
CVE-2026-96273
Description
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, when imported, causes the application to stall and prevents resource cleanup or graceful shutdown.
Patches
Vulnerability mechanics
References
5- github.com/NationalSecurityAgency/ghidra/blob/Ghidra_12.1.3_build/Ghidra/Framework/Project/src/main/java/ghidra/framework/data/OptionsDB.javanvd
- github.com/NationalSecurityAgency/ghidra/commit/594da048431aab082a9da7c4a965874d07d33310nvd
- github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_12.1.4_buildnvd
- github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-4w7g-wmg8-fgv5nvd
- www.vulncheck.com/advisories/ghidra-before-12.1.4-denial-of-service-via-crafted-databasenvd
News mentions
0No linked articles in our index yet.