CVE-2026-8695: Radare RADARE2

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list processing.

Affected products

  • Radare RADARE2: up to and including 6.1.4

Published 2026-05-15. Last modified 2026-06-17.