CVE-2026-81880
Last modified
CVE-2026-81880 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete relocation records in the input. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete relocation records in the input. The vulnerability is triggered by normal binary-format auto-detection of a small crafted Apple PEF file. The loader could perform up to 268,435,456 relocation-section iterations and repeated buffer operations after record offsets passed the end of the file. This can cause denial of service through excessive CPU consumption and prolonged processing. This issue is fixed in version 6.2.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Radare | Radare2 | < 6.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-81880?
How severe is CVE-2026-81880?
How do I fix CVE-2026-81880?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81872OpenTelemetry-Go is the Go implementation of OpenTelemetry. …6.3
- CVE-2026-81875HAPI FHIR is a complete implementation of the HL7 FHIR stand…7.5
- CVE-2026-81876HAPI FHIR is a complete implementation of the HL7 FHIR stand…7.5
- CVE-2026-81878radare2 is a UNIX-like reverse engineering framework and com…5.5
- CVE-2026-81879radare2 is a UNIX-like reverse engineering framework and com…6.1
- CVE-2026-8188A vulnerability has been found in Wavlink NU516U1 M16U1_V240…8.8
- CVE-2026-81881radare2 is a UNIX-like reverse engineering framework and com…4.4
- CVE-2026-81882radare2 is a UNIX-like reverse engineering framework and com…6.1
- CVE-2026-81883radare2 is a UNIX-like reverse engineering framework and com…3.3
- CVE-2026-81884radare2 is a UNIX-like reverse engineering framework and com…2.5
- CVE-2026-81885radare2 is a UNIX-like reverse engineering framework and com…5.5
- CVE-2026-81886radare2 is a UNIX-like reverse engineering framework and com…5.5
Are you affected by CVE-2026-81880?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
