CVE-2026-22780: Rizin

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.

Affected products

  • Rizin Rizin: before 0.8.2 (fixed in 0.8.2)

Published 2026-02-02. Last modified 2026-06-17.