Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis. | |
| Title | Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T15:09:15.581Z
Reserved: 2026-05-31T11:54:34.994Z
Link: CVE-2026-49497
Updated: 2026-06-10T15:09:07.852Z
Status : Analyzed
Published: 2026-06-10T14:16:34.643
Modified: 2026-06-11T19:50:28.753
Link: CVE-2026-49497
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:42:14Z