A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption.

This vulnerability is referenced as CVE-2026-4174. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The existence of this vulnerability is still disputed at present.

You should upgrade the affected component.

The code maintainer states that, “[he] wont consider this bug a DoS”.