CVE-2026-52759: Nsa Ghidra

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command count value, forcing the parser to allocate excessive heap memory without validating file size, crashing the Ghidra JVM.

Affected products

  • Nsa Ghidra: before 12.1.1 (fixed in 12.1.1)

Published 2026-06-10. Last modified 2026-06-17.