{
  "project": "MicroPython",
  "repo_url": "https://github.com/micropython/micropython",
  "description": "Python for microcontrollers.",
  "release": {
    "filename": "oss-micropython__micropython.cdx.json",
    "analysed_at": "2026-10-11T07:00:20.631Z"
  },
  "computed_at": "2026-10-11T13:04:04.490Z",
  "summary": {
    "fix": 3,
    "look": 2,
    "clear": 1,
    "unwatched": 33,
    "missed_by_nvd_scanners": 13
  },
  "components": 39,
  "fix": [
    {
      "name": "mbedtls",
      "version": "3.6.6",
      "action": "Upgrade to 3.6.7 or later",
      "vulns": [
        {
          "id": "CVE-2026-50580",
          "title": "Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecdhe-psk-client-buffer-overflow/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50580"
          ]
        },
        {
          "id": "CVE-2026-50579",
          "title": "Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-use-after-free-pkcs7-free-reused-context/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50579"
          ]
        },
        {
          "id": "CVE-2026-50713",
          "title": "Heap corruption with early renegotiation after corrupted record in DTLS",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-heap-corruption-early-renegotiation-corrupted-dtls-record/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50713"
          ]
        },
        {
          "id": "CVE-2026-50584",
          "title": "ChaCha20 counter overflow can reuse keystream",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-chacha20-counter-overflow-keystream-reuse/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50584"
          ]
        },
        {
          "id": "CVE-2026-50587",
          "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-rsa-pkcs1-v15-decryption-timing-side-channel/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50587"
          ]
        },
        {
          "id": "CVE-2026-73096",
          "title": "TLS 1.3 early data integrity failure due to buffered plaintext across key change",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls13-early-data-integrity-failure-key-change/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73096"
          ]
        },
        {
          "id": "CVE-2026-50585",
          "title": "Incomplete context reset in mbedtls_ssl_session_reset()",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ssl-session-reset-incomplete-context-reset/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50585"
          ]
        },
        {
          "id": "CVE-2026-54441",
          "title": "Signature algorithm restrictions not enforced on certificate chain",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-signature-algorithm-restrictions-certificate-chain/",
            "https://www.cve.org/CVERecord?id=CVE-2026-54441"
          ]
        },
        {
          "id": "CVE-2026-73064",
          "title": "A random generator fault can compromise TLS data integrity",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-random-generator-fault-tls-integrity/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73064"
          ]
        },
        {
          "id": "CVE-2025-66442",
          "title": "Compiler-induced constant-time violations",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-66442",
            "https://www.cve.org/CVERecord?id=CVE-2025-66442"
          ]
        },
        {
          "id": "CVE-2026-50640",
          "title": "Ignored TLS 1.3 resumption secret derivation error",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ignored-tls13-resumption-secret-derivation-error/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50640"
          ]
        },
        {
          "id": "CVE-2026-50583",
          "title": "Out-of-bounds read when parsing a zero-length ECC public key",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-zero-length-ecc-public-key-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50583"
          ]
        },
        {
          "id": "CVE-2026-50588",
          "title": "Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecjpake-serverkeyexchange-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50588"
          ]
        },
        {
          "id": "CVE-2026-50586",
          "title": "Information disclosure in TLS 1.2 NewSessionTicket",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-newsessionticket-information-disclosure/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50586"
          ]
        }
      ]
    },
    {
      "name": "btstack",
      "version": "1.5.6.2",
      "action": "Upgrade to 1.8.1 or later",
      "vulns": [
        {
          "id": "CVE-2026-28527",
          "title": "BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY",
          "severity": "low",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-28527",
            "https://www.cve.org/CVERecord?id=CVE-2026-28527"
          ]
        },
        {
          "id": "CVE-2026-28528",
          "title": "BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET",
          "severity": "low",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-28528",
            "https://www.cve.org/CVERecord?id=CVE-2026-28528"
          ]
        },
        {
          "id": "CVE-2026-28526",
          "title": "BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA",
          "severity": "low",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-28526",
            "https://www.cve.org/CVERecord?id=CVE-2026-28526"
          ]
        },
        {
          "id": "CVE-2026-93015",
          "title": "BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-93015"
          ]
        }
      ]
    },
    {
      "name": "lwip",
      "version": "2.2.1",
      "action": "No fixed version given. Read the advisory.",
      "vulns": [
        {
          "id": "CVE-2020-22283",
          "title": "Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2020-22283",
            "https://www.cve.org/CVERecord?id=CVE-2020-22283"
          ]
        },
        {
          "id": "CVE-2026-8836",
          "title": "lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-8836"
          ]
        }
      ]
    }
  ],
  "look": [
    {
      "name": "nimble",
      "version": "42849560ba7906f023f61e5f7ff3709ba2c1dfca",
      "action": "A vendor fork: check whether it carries the fixes",
      "vulns": [
        {
          "id": "CVE-2024-51569",
          "title": "Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-51569",
            "https://www.cve.org/CVERecord?id=CVE-2024-51569"
          ]
        },
        {
          "id": "CVE-2026-45813",
          "title": "Incorrect data validation in BASS add/modify source operation",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45813",
            "https://www.cve.org/CVERecord?id=CVE-2026-45813"
          ]
        },
        {
          "id": "CVE-2024-24746",
          "title": "Denial of service in NimBLE Bluetooth stack",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-24746",
            "https://www.cve.org/CVERecord?id=CVE-2024-24746"
          ]
        },
        {
          "id": "CVE-2026-45815",
          "title": "Remote reachable assertion in ATT Read Multiple Variable Response handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45815",
            "https://www.cve.org/CVERecord?id=CVE-2026-45815"
          ]
        },
        {
          "id": "CVE-2026-45811",
          "title": "Buffer overflow in socket HCI transport",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45811",
            "https://www.cve.org/CVERecord?id=CVE-2026-45811"
          ]
        },
        {
          "id": "CVE-2025-52435",
          "title": "Invalid error handling in pause encryption procedure in NimBLE controller",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-52435",
            "https://www.cve.org/CVERecord?id=CVE-2025-52435"
          ]
        },
        {
          "id": "CVE-2025-62235",
          "title": "Incorrect handling of SMP Security Request could lead to undesirable pairing",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-62235",
            "https://www.cve.org/CVERecord?id=CVE-2025-62235"
          ]
        },
        {
          "id": "CVE-2025-53477",
          "title": "NULL Pointer Dereference in NimBLE host HCI layer",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53477",
            "https://www.cve.org/CVERecord?id=CVE-2025-53477"
          ]
        },
        {
          "id": "CVE-2026-45816",
          "title": "NULL pointer dereference vulnerability in SMP LTK request",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45816",
            "https://www.cve.org/CVERecord?id=CVE-2026-45816"
          ]
        },
        {
          "id": "CVE-2026-45812",
          "title": "OOB Read via sizeof(pointer) in Legacy Advertising Report Handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45812",
            "https://www.cve.org/CVERecord?id=CVE-2026-45812"
          ]
        },
        {
          "id": "CVE-2024-47249",
          "title": "Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-47249",
            "https://www.cve.org/CVERecord?id=CVE-2024-47249"
          ]
        },
        {
          "id": "CVE-2024-47248",
          "title": "Buffer overflow in NimBLE MESH Bluetooth stack",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-47248",
            "https://www.cve.org/CVERecord?id=CVE-2024-47248"
          ]
        },
        {
          "id": "CVE-2024-47250",
          "title": "Lack of input validation in HCI advertising report could lead to potential out-of-bound access",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-47250",
            "https://www.cve.org/CVERecord?id=CVE-2024-47250"
          ]
        },
        {
          "id": "CVE-2026-46452",
          "title": "Mesh Proxy SAR reassembly unbounded append and unchecked failure",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-46452",
            "https://www.cve.org/CVERecord?id=CVE-2026-46452"
          ]
        },
        {
          "id": "CVE-2025-53470",
          "title": "Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver",
          "severity": "low",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53470",
            "https://www.cve.org/CVERecord?id=CVE-2025-53470"
          ]
        }
      ]
    },
    {
      "name": "axtls",
      "version": "2.1.5..",
      "action": "Version numbers can't settle this. Have a look.",
      "vulns": [
        {
          "id": "CVE-2019-10013",
          "title": "The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem",
          "severity": "high",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2019-10013",
            "https://www.cve.org/CVERecord?id=CVE-2019-10013"
          ]
        },
        {
          "id": "CVE-2019-9689",
          "title": "process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi",
          "severity": "high",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2019-9689",
            "https://www.cve.org/CVERecord?id=CVE-2019-9689"
          ]
        },
        {
          "id": "CVE-2023-33613",
          "title": "axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. T",
          "severity": "medium",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2023-33613",
            "https://www.cve.org/CVERecord?id=CVE-2023-33613"
          ]
        }
      ]
    }
  ],
  "unwatched": [
    {
      "name": "alif-ensemble-cmsis-dfp",
      "version": "2.0.0"
    },
    {
      "name": "alif-security-toolkit",
      "version": "1.104.0.."
    },
    {
      "name": "arduino-lib-mpy",
      "version": "8312406d6cd1a19683500f153b33fba7a8414127"
    },
    {
      "name": "asf4",
      "version": "84f56af13292d8f32c40acbd949bde698ddd4507"
    },
    {
      "name": "async-transfer",
      "version": "1.1.0"
    },
    {
      "name": "berkeley-db-1-xx",
      "version": "0f3bb6947c2f57233916dccd7bb425d7bf86e5a6"
    },
    {
      "name": "cmsis-5",
      "version": "5.9.0"
    },
    {
      "name": "cmsis-6",
      "version": "6.3.0"
    },
    {
      "name": "core-lib",
      "version": "1.7.0"
    },
    {
      "name": "cyw43-driver",
      "version": "1.1.1"
    },
    {
      "name": "esp-hosted",
      "version": "2.7.0"
    },
    {
      "name": "esp-wifi-remote",
      "version": "0.15.2"
    },
    {
      "name": "fsp",
      "version": "4.4.0"
    },
    {
      "name": "lan867x",
      "version": "~1.0.0"
    },
    {
      "name": "libffi",
      "version": "3.4.6"
    },
    {
      "name": "libhydrogen",
      "version": "173f728ee2c627f80fd0322473e16467f259558d"
    },
    {
      "name": "libmetal",
      "version": "2023.10.0"
    },
    {
      "name": "mdns",
      "version": "~1.3.0"
    },
    {
      "name": "micropython",
      "version": "1.29.0"
    },
    {
      "name": "micropython-lib",
      "version": "1.29.0"
    },
    {
      "name": "mtb-dsl-pse8xxgp",
      "version": "1.3.0"
    },
    {
      "name": "mtb-ipc",
      "version": "1.2.0"
    },
    {
      "name": "mtb-srf",
      "version": "1.1.1"
    },
    {
      "name": "nrfx",
      "version": "3.14.0"
    },
    {
      "name": "nxp-driver",
      "version": "a298e8a3cad2df737de020bbeac4ee2147d189ca"
    },
    {
      "name": "open-amp",
      "version": "2023.10.0"
    },
    {
      "name": "pico-sdk",
      "version": "2.3.0"
    },
    {
      "name": "se-rt-services-utils",
      "version": "1.2.0"
    },
    {
      "name": "serial-memory",
      "version": "3.1.0"
    },
    {
      "name": "stm32lib",
      "version": "1.8.1.."
    },
    {
      "name": "target-kit-pse84-ai",
      "version": "1.3.0"
    },
    {
      "name": "tinyusb",
      "version": "cherrypick/dwc2_zlp_fix"
    },
    {
      "name": "wiznet-iolibrary-driver",
      "version": "3.1.3.."
    }
  ]
}