Threat intelligence dashboard
CVE-2026-100504high

Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.

Risk score

7.3

CVSS 4.0

Vendor
NationalSecurityAgency
Product
ghidra
CWE
CWE-787
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

ghidra

NationalSecurityAgency

Version / rangeStatusType
0 to 12.1.4affectedcustom

Technical metrics

7.3

CVSS 4.0

Severity
high
Source
VulnCheck
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

7.0

CVSS 3.1

Severity
high
Source
VulnCheck
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H