Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
1.9
CVE-2026-14759: radare2 Java Parser Buffer Overflow Risk
CVE-2026-14759
Summary
A security flaw in radare2's Java parser can cause a buffer overflow, allowing an attacker to execute malicious code on a local system. This vulnerability has been publicly exploited, and we recommend updating to the latest version to prevent potential attacks.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| radare | radare2 |
< 6.1.8 cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* |
Original title
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava...
Original description
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.
nvd CVSS2.0
1.7
nvd CVSS3.1
3.3
nvd CVSS4.0
1.9
Vulnerability type
CWE-119
Buffer Overflow
CWE-122
Heap-based Buffer Overflow
- https://github.com/radareorg/radare2/
- https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d1...
- https://github.com/radareorg/radare2/issues/26043
- https://vuldb.com/cve/CVE-2026-14759
- https://vuldb.com/submit/850383
- https://vuldb.com/vuln/376348
- https://vuldb.com/vuln/376348/cti
Published: 5 Jul 2026 · Updated: 8 Jul 2026 · First seen: 5 Jul 2026