radare has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-125 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-81879Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset42CVE-2026-81878Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset42CVE-2026-81880Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset30CVE-2026-81882Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset18CVE-2026-81881Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset18
radare vulnerabilities
CVEs affecting radare, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-81881Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata sect…
CVE-2026-81878Medium· 5.5PoCradare2 is a UNIX-like reverse engineering framework and command-line toolset
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without reje…
CVE-2026-81880Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded b…
CVE-2026-81882Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized U…
CVE-2026-81879Medium· 5.5PoCradare2 is a UNIX-like reverse engineering framework and command-line toolset
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but s…