Open-source firmware report

MicroPython

Python for microcontrollers.

github.com/micropython/micropython · 39 components read from oss-micropython__micropython.cdx.json (analysed 2026-10-11) · checked against today's advisories 2026-10-11

Vulnerabilities affecting this build

5reported by a scanner that checks NVD
20reported by Firmpath
13only in vendors' own advisories, or not yet in NVD for this version

2 more come from OSV and were not checked against NVD; counted as ours, claimed for neither.

3to upgrade
2to look at
1clear
33no advisory source

To upgrade

A published vulnerability affects the version this build uses.

mbedtls 3.6.6 Upgrade to 3.6.7 or later14 vulnerabilities · an NVD scanner reports 1
btstack 1.5.6.2 Upgrade to 1.8.1 or later4 vulnerabilities · an NVD scanner reports 3
  • CVE-2026-28527 low
    BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY
  • CVE-2026-28528 low
    BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET
  • CVE-2026-28526 low
    BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA
  • CVE-2026-93015 OSV
    BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
lwip 2.2.1 No fixed version given. Read the advisory.2 vulnerabilities · an NVD scanner reports 1
  • CVE-2020-22283 silabs high
    Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
  • CVE-2026-8836 OSV
    lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow

To look at

Version numbers cannot settle these: usually a vendor's fork that may already carry the fix.

nimble 42849560ba7906f023f61e5f7ff3709ba2c1dfca A vendor fork: check whether it carries the fixes15 vulnerabilities · an NVD scanner reports 15
  • CVE-2024-51569 nimble high
    Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
  • CVE-2026-45813 nimble high
    Incorrect data validation in BASS add/modify source operation
  • CVE-2024-24746 nimble high
    Denial of service in NimBLE Bluetooth stack
  • CVE-2026-45815 nimble high
    Remote reachable assertion in ATT Read Multiple Variable Response handler
  • CVE-2026-45811 nimble high
    Buffer overflow in socket HCI transport
  • CVE-2025-52435 nimble high
    Invalid error handling in pause encryption procedure in NimBLE controller
  • CVE-2025-62235 nimble high
    Incorrect handling of SMP Security Request could lead to undesirable pairing
  • CVE-2025-53477 nimble high
    NULL Pointer Dereference in NimBLE host HCI layer
  • CVE-2026-45816 nimble high
    NULL pointer dereference vulnerability in SMP LTK request
  • CVE-2026-45812 nimble medium
    OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
  • CVE-2024-47249 nimble medium
    Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
  • CVE-2024-47248 nimble medium
    Buffer overflow in NimBLE MESH Bluetooth stack
  • CVE-2024-47250 nimble medium
    Lack of input validation in HCI advertising report could lead to potential out-of-bound access
  • CVE-2026-46452 nimble medium
    Mesh Proxy SAR reassembly unbounded append and unchecked failure
  • CVE-2025-53470 nimble low
    Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
axtls 2.1.5.. Version numbers can't settle this. Have a look.3 vulnerabilities · an NVD scanner reports 3
  • CVE-2019-10013 high
    The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem
  • CVE-2019-9689 high
    process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi
  • CVE-2023-33613 medium
    axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. T

No advisory source

No vendor advisory, NVD or OSV record has ever named these. That is not the same as safe: nobody is publishing about them.

How this was made, and what it is not

We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.

It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.