Description
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.
Published: 2026-09-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote exploitation that may lead to memory corruption or application crash
Action: Patch
AI Analysis

Impact

A flaw in JusticeRage Manalyze version 1.0.0 causes an integer underflow when parsing the PE debug section. The mishandling of the misc.Length argument can lead to an out‑of‑bounds access that may corrupt memory or crash the application. The description states that the attack can be performed from remote, indicating that an attacker could supply a malicious PE file over the network and trigger the vulnerability.

Affected Systems

The affected product is JusticeRage Manalyze, a tool used to analyze portable executable files. Only the 1.0.0 release is known to contain the flaw; later versions incorporate the patch listed in commit 3e299685759f4f767088871de58c5d07f98ee382.

Risk and Exploitability

The CVSS score of 5.3 places the bug in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no known exploitation evidence yet. However, because the attack vector is remote, the likelihood of exploitation remains non‑zero and could lead to denial of service or memory corruption if successful.

Generated by OpenCVE AI on September 20, 2026 at 23:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 3e299685759f4f767088871de58c5d07f98ee382 to fix the integer underflow (CWE‑189) and signedness underflow (CWE‑191) in the PE Parser of Manalyze.
  • Deploy the patched version so all users run the updated binary or repository clone, thereby mitigating the CWE‑189 and CWE‑191 vulnerabilities.
  • If the patch cannot be applied immediately, restrict Manalyze to processing only locally trusted PE files or execute it inside a sandbox when handling untrusted input, limiting damage from potential exploitation of the integer and signedness underflows.

Generated by OpenCVE AI on September 20, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.
Title JusticeRage Manalyze PE Parser pe.cpp _parse_debug integer underflow
First Time appeared Justicerage
Justicerage manalyze
Weaknesses CWE-189
CWE-191
CPEs cpe:2.3:a:justicerage:manalyze:*:*:*:*:*:*:*:*
Vendors & Products Justicerage
Justicerage manalyze
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Justicerage Manalyze
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T19:45:50.468Z

Reserved: 2026-09-20T08:07:29.403Z

Link: CVE-2026-94090

cve-icon Vulnrichment

Updated: 2026-09-21T19:45:46.935Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T22:16:30.703

Modified: 2026-09-21T20:17:40.360

Link: CVE-2026-94090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:03Z

Weaknesses