CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54389

mediumCVSS 5.5covered by 1 sourcefirst seen 2026-08-20
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserialization routine reads all remaining parameters into an unbounded list, causing uncontrolled heap growth that triggers an OutOfMemoryError which bypasses exception handling and crashes the application.

⚡ Watch CVE-2026-54389

Get an email if CVE-2026-54389 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-54389

CVE.org record

Embed the live status

CVE-2026-54389 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54389 status](https://www.csirts.com/badge/CVE-2026-54389)](https://www.csirts.com/cve/CVE-2026-54389)