Allocation of Resources Without Limits or Throttling in Ghidra - #VU131575

 

Allocation of Resources Without Limits or Throttling in Ghidra - #VU131575

Published: May 15, 2026


Vulnerability identifier: #VU131575
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in ExportTrie.parseTrie() when parsing a crafted Mach-O export trie. A remote attacker can trick the victim into opening a crafted Mach-O binary to cause a denial of service.

User interaction is required to open the crafted file, and the issue affects both GUI and headless mode.


Affected software

Ghidra

Remediation

Install security update from vendor's website.

Ghidra - update to 12.1

External References

Related Security Bulletins