Post

CVE-2026-94090 - JusticeRage Manalyze PE Parser Vulnerability

CVE-2026-94090 - JusticeRage Manalyze PE Parser Vulnerability

CVE-2026-94090 - JusticeRage Manalyze PE Parser Vulnerability

A security flaw, identified as CVE-2026-94090, has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp in the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. This attack may be performed remotely.

Patch Information

A patch has been identified as 3e299685759f4f767088871de58c5d07f98ee382. It is crucial to apply this patch to remediate the issue.

Vulnerability Details

Details regarding this vulnerability were received on September 20, 2026. The vulnerability has been assigned a CVSS V4.0 score of AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X. Additionally, a CVSS V3.1 score of AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L was added, as well as a CVSS V2 score of AV:N/AC:L/Au:N/C:P/I:P/A:P. The vulnerability is also associated with CWE-189 and CWE-191.

Impact

The report states that “The following products are affected by CVE-2026-94090 vulnerability.” However, it notes that “No affected product recorded yet,” clarifying that even if cvefeed.io is aware of the exact versions of the products that are affected, this information is not represented in the table below.

To address this flaw, it is essential to apply the patch identified by commit 3e299685759f4f767088871de58c5d07f98ee382. Further details and references, including links to the JusticeRage/Manalyze GitHub repository and VulDB, have been provided.

For more information, you can read the complete article here: Read full article

🚀 Stay informed and secure!

This post is licensed under CC BY 4.0 by the author.