LIVE · cybersecurity feed
Live wire
vendor

Zephyrproject

25 CVEs published in the last four months. Exploited flaws first.

Critical1
High22
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-50679.8criticalzephyrA remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by 88d ago
CVE-2026-106438.7highzephyrZephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated th70d ago
CVE-2026-106738.3highzephyrThe Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received52d ago
CVE-2026-108498.2highzephyrThe hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the upda33d ago
CVE-2026-106728.2highzephyrsubsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (conte53d ago
CVE-2026-76568.1highzephyrThe IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input68d ago
CVE-2026-106668.1highzephyrparse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copi55d ago
CVE-2026-106788.1highzephyrThe MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-registe46d ago
CVE-2026-106697.8highzephyrOn Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c53d ago
CVE-2026-106677.8highzephyrZephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a do55d ago
CVE-2026-106807.6highzephyrThe Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host46d ago
CVE-2026-50687.6highzephyrA remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE C88d ago
CVE-2026-106857.6highzephyrThe Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c i36d ago
CVE-2026-80237.5highzephyrZephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS68d ago
CVE-2026-133517.5highzephyrZephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a sma72d ago
CVE-2026-106467.4highzephyrZephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a sta69d ago
CVE-2026-106657.4highzephyrIn Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an55d ago
CVE-2026-113687.1highzephyrThe Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning32d ago
CVE-2026-106417.1highzephyrZephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c80d ago
CVE-2026-106517.1highzephyrbt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the75d ago
CVE-2026-106587.1highzephyrbt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is se75d ago
CVE-2026-106717.1highzephyrIn Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used 53d ago
CVE-2026-108487highzephyrThe OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/34d ago
CVE-2026-41796.1mediumzephyrIssues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.173d ago
CVE-2026-08493.8lowzephyrMalformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto d173d ago

Filter the full tracker by Zephyrproject