MicroPython
Python for microcontrollers.
Vulnerabilities affecting this build
To upgrade
mbedtls 3.6.6 Upgrade to 3.6.7 or later14 vulnerabilities · an NVD scanner reports 1
- CVE-2026-50580 mbedtls missed by NVD scannershigh
Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake
- CVE-2026-50579 mbedtls missed by NVD scannershigh
Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context
- CVE-2026-50713 mbedtls missed by NVD scannershigh
Heap corruption with early renegotiation after corrupted record in DTLS
- CVE-2026-50584 mbedtls missed by NVD scannersmedium
ChaCha20 counter overflow can reuse keystream
- CVE-2026-50587 mbedtls missed by NVD scannersmedium
Timing side-channel in RSA PKCS#1 v1.5 decryption
- CVE-2026-73096 mbedtls missed by NVD scannersmedium
TLS 1.3 early data integrity failure due to buffered plaintext across key change
- CVE-2026-50585 mbedtls missed by NVD scannersmedium
Incomplete context reset in mbedtls_ssl_session_reset()
- CVE-2026-54441 mbedtls missed by NVD scannerslow
Signature algorithm restrictions not enforced on certificate chain
- CVE-2026-73064 mbedtls missed by NVD scannerslow
A random generator fault can compromise TLS data integrity
- CVE-2025-66442 mbedtls low
Compiler-induced constant-time violations
- CVE-2026-50640 mbedtls missed by NVD scannerslow
Ignored TLS 1.3 resumption secret derivation error
- CVE-2026-50583 mbedtls missed by NVD scannerslow
Out-of-bounds read when parsing a zero-length ECC public key
- CVE-2026-50588 mbedtls missed by NVD scannerslow
Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing
- CVE-2026-50586 mbedtls missed by NVD scannerslow
Information disclosure in TLS 1.2 NewSessionTicket
btstack 1.5.6.2 Upgrade to 1.8.1 or later4 vulnerabilities · an NVD scanner reports 3
- CVE-2026-28527 low
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY
- CVE-2026-28528 low
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET
- CVE-2026-28526 low
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA
- CVE-2026-93015 OSV
BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
lwip 2.2.1 No fixed version given. Read the advisory.2 vulnerabilities · an NVD scanner reports 1
- CVE-2020-22283 silabs high
Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
- CVE-2026-8836 OSV
lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow
To look at
nimble 42849560ba7906f023f61e5f7ff3709ba2c1dfca A vendor fork: check whether it carries the fixes15 vulnerabilities · an NVD scanner reports 15
- CVE-2024-51569 nimble high
Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
- CVE-2026-45813 nimble high
Incorrect data validation in BASS add/modify source operation
- CVE-2024-24746 nimble high
Denial of service in NimBLE Bluetooth stack
- CVE-2026-45815 nimble high
Remote reachable assertion in ATT Read Multiple Variable Response handler
- CVE-2026-45811 nimble high
Buffer overflow in socket HCI transport
- CVE-2025-52435 nimble high
Invalid error handling in pause encryption procedure in NimBLE controller
- CVE-2025-62235 nimble high
Incorrect handling of SMP Security Request could lead to undesirable pairing
- CVE-2025-53477 nimble high
NULL Pointer Dereference in NimBLE host HCI layer
- CVE-2026-45816 nimble high
NULL pointer dereference vulnerability in SMP LTK request
- CVE-2026-45812 nimble medium
OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
- CVE-2024-47249 nimble medium
Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
- CVE-2024-47248 nimble medium
Buffer overflow in NimBLE MESH Bluetooth stack
- CVE-2024-47250 nimble medium
Lack of input validation in HCI advertising report could lead to potential out-of-bound access
- CVE-2026-46452 nimble medium
Mesh Proxy SAR reassembly unbounded append and unchecked failure
- CVE-2025-53470 nimble low
Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
axtls 2.1.5.. Version numbers can't settle this. Have a look.3 vulnerabilities · an NVD scanner reports 3
- CVE-2019-10013 high
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem
- CVE-2019-9689 high
process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi
- CVE-2023-33613 medium
axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. T
No advisory source
- alif-ensemble-cmsis-dfp 2.0.0
- alif-security-toolkit 1.104.0..
- arduino-lib-mpy 8312406d6cd1a19683500f153b33fba7a8414127
- asf4 84f56af13292d8f32c40acbd949bde698ddd4507
- async-transfer 1.1.0
- berkeley-db-1-xx 0f3bb6947c2f57233916dccd7bb425d7bf86e5a6
- cmsis-5 5.9.0
- cmsis-6 6.3.0
- core-lib 1.7.0
- cyw43-driver 1.1.1
- esp-hosted 2.7.0
- esp-wifi-remote 0.15.2
- fsp 4.4.0
- lan867x ~1.0.0
- libffi 3.4.6
- libhydrogen 173f728ee2c627f80fd0322473e16467f259558d
- libmetal 2023.10.0
- mdns ~1.3.0
- micropython 1.29.0
- micropython-lib 1.29.0
- mtb-dsl-pse8xxgp 1.3.0
- mtb-ipc 1.2.0
- mtb-srf 1.1.1
- nrfx 3.14.0
- nxp-driver a298e8a3cad2df737de020bbeac4ee2147d189ca
- open-amp 2023.10.0
- pico-sdk 2.3.0
- se-rt-services-utils 1.2.0
- serial-memory 3.1.0
- stm32lib 1.8.1..
- target-kit-pse84-ai 1.3.0
- tinyusb cherrypick/dwc2_zlp_fix
- wiznet-iolibrary-driver 3.1.3..
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.