CVE-2024-58350: Nsa Ghidra

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.

Affected products

  • Nsa Ghidra: before 11.2 (fixed in 11.2)

Published 2026-06-10. Last modified 2026-07-14.