# rizin 0.9.1

UNIX-like reverse engineering framework and command-line toolset.

Snapshot of gominimal/pkgs commit `75fcc0c216a965906cff4df6f7c16cf03acdca5b` (pushed 2026-08-23T17:32:57.000Z).

## Install

```sh
min add rizin
```

## Direct advisories

| ID | Severity | CVSS | Fix status | Fixed version | Summary |
| --- | --- | --- | --- | --- | --- |
| CVE-2026-45324 | LOW | 3.3 | fixed | — | Rizin: Double free in cmd_search.c |

## Transitive advisories

6 advisories inherited through runtime dependencies:

- CVE-2026-5435 (HIGH) via glibc
- CVE-2026-6238 (MEDIUM) via glibc
- GHSA-q7rw-r7qq-2hx6 (UNKNOWN) via pcre2
- OSV-2026-343 (HIGH) via pcre2
- CVE-2026-14456 (HIGH) via openssl
- CVE-2026-54876 (HIGH) via openssl

## Dependencies

- Build (15): base, toolchain, gcc, meson, ninja, pkgconf, python, glibc, zlib, zstd, xz, lz4, pcre2, openssl, tree-sitter
- Runtime (9): bash, glibc, zlib, zstd, xz, lz4, pcre2, openssl, tree-sitter

## Scorecard

| Category | Score | Band |
| --- | --- | --- |
| supply-chain | 40 | low |
| advisories | 25 | low |
| quality | 45 | low |
| maintenance | 100 | perfect |
| licence | 100 | perfect |

## Links

- Homepage: https://rizin.re
- Package page (HTML): https://minimal.dev/pkgs/rizin
- JSON API (floats latest): https://minimal.dev/api/pkgs/rizin.json
- SBOM (CycloneDX 1.5): https://minimal.dev/api/pkgs/rizin/sbom.json
