radareorg.radare2 is vulnerable to Out-of-bounds Read
68
Medium Risk
Affected versions of this package contain an out-of-bounds memory access the regex engine. Missing validation of offsets and lengths allows crafted binaries to trigger invalid pointer arithmetic and read or write outside allocated buffers during comparisons. This can result in memory corruption or a crash when radareorg.radare2 processes malicious input files. The patch adds boundary checks and null validations before using computed ranges.
You are affected if you are using a version that falls within the vulnerable range.
radareorg.radare2 is vulnerable to Out-of-bounds Read in versions 1.3.0 - 6.1.1.
Upgrade the radareorg.radare2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant