CVE-2026-95958
Received Received - Intake

Integer Underflow in Manalyze PE Parser

Vulnerability report for CVE-2026-95958, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: VulDB

Description

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
justicerage manalyze 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow in the PE::_parse_relocations function of JusticeRage Manalyze 1.0.0. It occurs when the BlockSize argument is manipulated, leading to incorrect calculations. The flaw exists in the PE parser component of the tool.

Detection Guidance

Since this vulnerability involves a flaw in the PE parser of Manalyze 1.0.0, detection would require analyzing PE files for malformed relocation or debug MISC data. Use Manalyze with plugins to scan suspicious executables for parsing errors or crashes during analysis.

Impact Analysis

An attacker could exploit this to cause unexpected behavior in Manalyze when parsing PE files. Since Manalyze is used for static analysis of executables, this could lead to incorrect analysis results or crashes. The attack requires local access to the system.

Mitigation Strategies

Apply the patch c372b6bbca9d8c63812be50596fefa4a79c65fd0 to update Manalyze to a fixed version. Avoid using Manalyze 1.0.0 for parsing untrusted PE files until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95958. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart