Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rizin

First CVE: Dec 13, 2021Active for: 5 yearsTotal CVEs: 20
36.9
VTI Score
Medium

Rizin is a reverse-engineering and binary-analysis framework that, despite a narrow product scope, occupies a prominent position in the security-research and vulnerability-analysis toolchain. The vulnerability footprint concentrates in the core Rizin tool itself and recurs through memory-safety and resource-management weakness classes including out-of-bounds writes, classic buffer overflows, improper memory-buffer bounds restrictions, unchecked resource allocation, and double-free conditions—exposures typical of a complex parser and disassembly engine handling untrusted binary inputs. Because Rizin is often run against adversary-controlled or unknown binaries as part of threat analysis and malware examination, memory-safety flaws in the parser chain can crash or corrupt analysis sessions, impacting the reliability of reverse-engineering workflows. Defenders and researchers using this tool should treat updates as relevant to analysis integrity and consider the memory-safety profile when processing suspected malicious or unstable binaries. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rizin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2021
4 years ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3674HIGH
A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of boun
Mar 24, 20237.825NONO
CVE-2022-36044HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from Luac files. A
Sep 6, 20227.825NONO
CVE-2022-36043HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to a double free in bobj.c:rz_bin_reloc_storage_free() when fre
Sep 6, 20227.825NONO
CVE-2022-36041HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when parsing Mach-O files. A user ope
Sep 6, 20227.825NONO
CVE-2022-36040HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from PYC(python) fi
Sep 6, 20227.825NONO
CVE-2022-36039HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to out-of-bounds write when parsing DEX files. A user opening a
Sep 6, 20227.825NONO
CVE-2021-43814HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when rev
Dec 13, 20217.825NONO
CVE-2024-31668CRITICAL
rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.
Dec 17, 20249.124NONO
CVE-2023-27590HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. In version 0.5.1 and prior, converting a GDB registers profile file into a Rizin register profile can r
Mar 14, 20237.824NONO
CVE-2022-36042HIGH
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from dyld cache fil
Sep 6, 20227.824NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
30%
65%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local17 (85.0%)
Network3 (15.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (30.0%)
Unknown0 (0.0%)
Required14 (70.0%)
Privileges Required
Low3 (15.0%)
High0 (0.0%)
None17 (85.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rizin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rizin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rizin's Products

View all 4 CNAs →

Top CWEs