OpenMQTTGateway
ESP32 gateway firmware bridging RF, BLE and infrared to MQTT.
Vulnerabilities affecting this build
To upgrade
nghttp2 1.41.0 Upgrade to 1.68.1 or later5 vulnerabilities · an NVD scanner reports 5
- CVE-2023-35945 high
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk
- CVE-2023-44487 high
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
- CVE-2026-27135 Siemens high
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
- CVE-2024-28182 medium
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6
- CVE-2026-58055 medium
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an
esp-idf 4.4.4 Move to 5.2.2: 4.4 is out of support since 2024-073 vulnerabilities · an NVD scanner reports 2
- CVE-2025-66409 espressif medium
Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling
- CVE-2025-55297 espressif medium
BluFi Example Memory Overflow Vulnerability
- CVE-2020-26142 espressif missed by NVD scannersmedium
Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame
cjson 1.7.15 Upgrade to 1.7.18 or later2 vulnerabilities · an NVD scanner reports 2
- CVE-2023-53154 low
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars
- CVE-2023-26819 low
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,999999999999999
protobuf-c 1.4.0 Upgrade to 1.4.1 or later2 vulnerabilities · an NVD scanner reports 2
- CVE-2022-48468 medium
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
- CVE-2022-33070 medium
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in proto
micro-ecc 1.0 No fixed version given. Read the advisory.1 vulnerability · an NVD scanner reports 1
- CVE-2020-27209 high
The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversar
To look at
mbedtls 2.28.1 A vendor fork: check whether it carries the fixes48 vulnerabilities · an NVD scanner reports 35
- CVE-2023-52353 silabs critical
Server refuses TLS 1.3 connection from peer if peer used TLS 1.2 previously
- CVE-2024-45158 silabs critical
Stack buffer overflow in ECDSA signature conversion functions
- CVE-2025-47917 silabs critical
Misleading memory management in mbedtls_x509_string_to_names()
- CVE-2024-45157 silabs critical
CTR_DRBG prioritized over HMAC_DRBG as the PSA DRBG
- CVE-2025-54764 silabs critical
Side channel in RSA key generation and operations
- CVE-2021-43615 silabs missed by NVD scannerscritical
Buffer overread in TLS stream 7.5 cipher suites
- CVE-2024-49195 silabs critical
Buffer underrun in pkwrite when writing an opaque key pair
- CVE-2024-30166 silabs critical
Stack buffer over read in TLS 1.3 server
- CVE-2025-59438 silabs critical
Padding oracle through timing of cipher error reporting
- CVE-2024-45159 silabs critical
Limited authentication bypass in TLS 1.3 optional client authentication
- CVE-2026-50580 mbedtls missed by NVD scannershigh
Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake
- CVE-2026-49300 mbedtls missed by NVD scannershigh
X.509 CA bit forgery via invalid basicConstraints extension
- CVE-2024-28836 silabs high
Vulnerability in devices operating as TLS 1.3 servers
- CVE-2026-25835 mbedtls high
PSA random generator cloning
- CVE-2024-23775 silabs high
Vulnerability in Mbed TLS to process x.509 extensions
- CVE-2024-23170 silabs high
Vulnerability in the implementation of RSA included in Mbed TLS
- CVE-2024-23744 silabs high
Vulnerability in devices operating as TLS 1.3 servers
- CVE-2024-28755 silabs high
Vulnerability in devices operating as TLS 1.3 servers
- CVE-2022-35409 silabs high
buffer-read overflow in certain DTLS Server configurations of Mbed TLS
- CVE-2024-28960 silabs high
Vulnerability affecting all VSE devices and TrustZone aware projects using PSA Crypto APIs with array arguments
- CVE-2021-43666 silabs high
Denial of Service the mbedtls_pkcs12_derivation function in Mbed TLS <=3.0.0
- CVE-2022-46393 silabs high
Potential heap overflow for certain configurations of Mbed TLS before 2.28.2 and 3.3.0
- CVE-2023-45199 silabs medium
Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets
- CVE-2026-50584 mbedtls missed by NVD scannersmedium
ChaCha20 counter overflow can reuse keystream
- CVE-2025-27810 silabs medium
Uninitialized stack memory used to compose ‘TLS finished’ message which may lead to authentication bypasses
- CVE-2026-50587 mbedtls missed by NVD scannersmedium
Timing side-channel in RSA PKCS#1 v1.5 decryption
- CVE-2025-49600 silabs medium
Unchecked return value in LMS verification allows signature bypass
- CVE-2025-52496 mbedtls medium
Race condition in AESNI support detection
- CVE-2022-46392 silabs medium
Side channel leakage in Mbed TLS RSA operations allows private key recovery
- CVE-2025-49087 silabs medium
Timing side-channel in block cipher decryption with PKCS#7 padding
- CVE-2026-35336 mbedtls missed by NVD scannersmedium
Possible buffer overflow in mbedtls_ecdh_calc_secret()
- CVE-2026-34872 mbedtls medium
FFDH: lack of contributory behaviour due to improper input validation
- CVE-2023-41097 silabs missed by NVD scannersmedium
Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information
- CVE-2021-45451 silabs medium
Vulnerabilities in PSA Crypto included in GSDK before 4.2.0
- A-00000492 silabs missed by NVD scannersmedium
A bug in TLS MAC length calculation may cause a buffer overread
- CVE-2025-52497 silabs medium
Heap buffer under-read when parsing PEM-encrypted material
- CVE-2026-54435 mbedtls missed by NVD scannersmedium
Side channel leak in ECC optimized modp
- CVE-2025-27809 silabs medium
Server hostname is not verified in a TLS handshake
- CVE-2025-49601 silabs medium
Out-of-bounds read in mbedtls_lms_import_public_key()
- CVE-2026-50585 mbedtls missed by NVD scannersmedium
Incomplete context reset in mbedtls_ssl_session_reset()
- CVE-2025-48965 silabs medium
NULL pointer dereference after using mbedtls_asn1_store_named_data()
- CVE-2023-43615 mbedtls medium
Buffer overread in TLS stream cipher suites
- CVE-2026-54441 mbedtls missed by NVD scannerslow
Signature algorithm restrictions not enforced on certificate chain
- CVE-2025-66442 mbedtls low
Compiler-induced constant-time violations
- CVE-2026-34871 mbedtls low
Entropy on Linux can fall back to /dev/urandom
- CVE-2026-34877 mbedtls low
Risk of insufficient protection of serialized session or context data leading to potential memory safety issues
- CVE-2026-50581 mbedtls missed by NVD scannerslow
Extended master secret calculation failure ignored
- CVE-2026-50586 mbedtls missed by NVD scannerslow
Information disclosure in TLS 1.2 NewSessionTicket
nimble 1.3.0.. A vendor fork: check whether it carries the fixes15 vulnerabilities · an NVD scanner reports 15
- CVE-2024-51569 nimble high
Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
- CVE-2026-45813 nimble high
Incorrect data validation in BASS add/modify source operation
- CVE-2024-24746 nimble high
Denial of service in NimBLE Bluetooth stack
- CVE-2026-45815 nimble high
Remote reachable assertion in ATT Read Multiple Variable Response handler
- CVE-2026-45811 nimble high
Buffer overflow in socket HCI transport
- CVE-2025-52435 nimble high
Invalid error handling in pause encryption procedure in NimBLE controller
- CVE-2025-62235 nimble high
Incorrect handling of SMP Security Request could lead to undesirable pairing
- CVE-2025-53477 nimble high
NULL Pointer Dereference in NimBLE host HCI layer
- CVE-2026-45816 nimble high
NULL pointer dereference vulnerability in SMP LTK request
- CVE-2026-45812 nimble medium
OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
- CVE-2024-47249 nimble medium
Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
- CVE-2024-47248 nimble medium
Buffer overflow in NimBLE MESH Bluetooth stack
- CVE-2024-47250 nimble medium
Lack of input validation in HCI advertising report could lead to potential out-of-bound access
- CVE-2026-46452 nimble medium
Mesh Proxy SAR reassembly unbounded append and unchecked failure
- CVE-2025-53470 nimble low
Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
lwip 2.1.2 A vendor fork: check whether it carries the fixes2 vulnerabilities · an NVD scanner reports 2
- CVE-2020-22283 silabs high
Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
- CVE-2020-22284 silabs high
Buffer overread vulnerability allows attackers to access sensitive information
libexpat version not stated Bundled in an SDK with no version of its own. Check the advisories.63 vulnerabilities · an NVD scanner reports 63
- CVE-2016-0718 critical
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a m
- CVE-2022-22822 critical
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22823 critical
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22824 critical
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-23852 critical
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_
- CVE-2022-25235 critical
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
- CVE-2022-25236 critical
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace
- CVE-2022-25315 critical
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
- CVE-2024-45491 critical
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on
- CVE-2024-45492 critical
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_grou
- CVE-2016-5300 high
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attacker
- CVE-2016-4472 high
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attacke
- CVE-2017-9233 high
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the p
- CVE-2017-11742 high
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local us
- CVE-2018-20843 high
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XM
- CVE-2019-15903 high
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too
- CVE-2021-45960 high
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can le
- CVE-2021-46143 high
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
- CVE-2022-22825 high
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22826 high
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22827 high
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-23990 high
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
- CVE-2022-25314 high
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
- CVE-2022-40674 high
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
- CVE-2022-43680 high
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEnti
- CVE-2023-52425 high
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in th
- CVE-2024-28757 high
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via
- CVE-2024-45490 high
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
- CVE-2026-66046 high
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAt
- CVE-2026-25210 Hitachi Energy medium
Hitachi Energy RTU500
- CVE-2026-32776 Hitachi Energy medium
Hitachi Energy RTU500
- CVE-2026-32777 Hitachi Energy medium
Hitachi Energy RTU500
- CVE-2009-3720 medium
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and o
- CVE-2009-3560 medium
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows con
- CVE-2012-0876 medium
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash c
- CVE-2012-1147 medium
readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor con
- CVE-2012-1148 medium
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to
- CVE-2013-0340 medium
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetE
- CVE-2015-1283 medium
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.24
- CVE-2012-6702 medium
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-d
- CVE-2022-25313 medium
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth
- CVE-2023-52426 medium
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
- CVE-2024-50602 medium
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_Stop
- CVE-2026-50219 medium
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars
- CVE-2026-56131 medium
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a
- CVE-2026-56132 medium
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array
- CVE-2026-56403 medium
libexpat before 2.8.2 has an integer overflow in storeAtts.
- CVE-2026-56404 medium
libexpat before 2.8.2 has an integer overflow in addBinding.
- CVE-2026-56405 medium
libexpat before 2.8.2 has an integer overflow in getAttributeId.
- CVE-2026-56406 medium
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse
- CVE-2026-56407 medium
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
- CVE-2026-56408 medium
libexpat before 2.8.2 has an integer overflow in copyString.
- CVE-2026-56409 medium
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
- CVE-2026-56410 medium
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
- CVE-2026-56411 medium
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
- CVE-2026-56412 medium
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking
- CVE-2026-76956 medium
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w
- CVE-2026-76957 medium
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur
- CVE-2025-66382 Siemens low
Siemens SINEC OS
- CVE-2026-24515 Hitachi Energy low
Hitachi Energy RTU500
- CVE-2026-32778 Hitachi Energy low
Hitachi Energy RTU500
- CVE-2026-41080 low
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
- CVE-2026-45186 low
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via
libcoap version not stated Bundled in an SDK with no version of its own. Check the advisories.16 vulnerabilities · an NVD scanner reports 16
- CVE-2023-30362 high
Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 al
- CVE-2024-31031 high
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leadin
- CVE-2025-65493 high
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic
- CVE-2025-65494 high
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker
- CVE-2025-65495 high
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t
- CVE-2025-34468 high
libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re
- CVE-2026-29013 high
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in
- CVE-2023-35862 medium
libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.
- CVE-2024-0962 medium
A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function g
- CVE-2025-65496 medium
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
- CVE-2025-65497 medium
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
- CVE-2025-65498 medium
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
- CVE-2025-65499 medium
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause
- CVE-2025-65500 medium
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
- CVE-2025-65501 medium
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of
- CVE-2025-59391 medium
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche
openthread version not stated A vendor fork with no release version. Check the vendor's notes on these advisories.8 vulnerabilities · an NVD scanner reports 1
- CVE-2023-41095 silabs high
Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
- CVE-2023-2626 openthread missed by NVD scannershigh
Missing Key ID Mode validation when processing 6LoWPAN frames
- CVE-2023-41096 silabs missed by NVD scannershigh
Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
- A-00000463 silabs missed by NVD scannershigh
OpenThread Vulnerability - Key ID Mode 2 Security
- CVE-2023-45199 silabs missed by NVD scannersmedium
Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets
- CVE-2023-41097 silabs missed by NVD scannersmedium
Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information
- CVE-2025-2329 silabs missed by NVD scannersmedium
Heavy traffic environment results in denial of service
- A-00000492 silabs missed by NVD scannersmedium
A bug in TLS MAC length calculation may cause a buffer overread
tinyxml2 version not stated Bundled in an SDK with no version of its own. Check the advisories.3 vulnerabilities · an NVD scanner reports 3
- CVE-2018-11210 critical
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml
- CVE-2024-50614 medium
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XM
- CVE-2024-50615 medium
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp
cryptoauthlib version not stated Bundled in an SDK with no version of its own. Check the advisories.2 vulnerabilities · an NVD scanner reports 2
- CVE-2019-16129 medium
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
- CVE-2019-16128 medium
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
coex-lib version not stated Bundled in an SDK with no version of its own. Check the advisories.1 vulnerability · an NVD scanner reports 0
- CVE-2021-26706 silabs missed by NVD scannersmedium
Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations
No advisory source
- a6lib fe873c9
- adafruit-ahtx0
- adafruit-neopixel
- adafruit-tsl2561 1.0.3
- adafruit-unified-sensor 1.1.4
- arduino-ina226 968a684
- arduino-log 6d1f14a
- arduino-lora f4a1d27
- arduinojson 6.18.5
- asio
- bearssl-esp8266
- cmock
- dallastemperature
- decoder 2.4.5
- dht-sensor-library 1.3.2
- emodbus 1.0.0
- esp-ble-mesh-lib
- esp-ieee802154-lib
- esp-nimble-cpp 2.5.0
- esp-phy-lib
- esp-thread-lib
- esp32-bt-lib
- esp32-wifi-lib
- esp32c2-bt-lib
- esp32c3-bt-lib
- esp32c5-bt-lib
- esp32c6-bt-lib
- esp32h2-bt-lib
- esp8266-arduino-core 3.1.2
- esp8266-mdns
- esp8266-nonos-sdk 2.2.0
- esp8266-oled-ssd1306 f96fd6a
- esp8266sdfat
- esp82xx-nonos-linklayer
- espilight b9dd7a1
- espsoftwareserial 8.0.1
- esptool 3.3.2
- ethernet
- fastled 3.9.15
- gfsuninverter 1.0.1
- i2c-temperature-sensors-derived-from-the-lm75
- irremoteesp8266 arduinov3
- libsodium
- littlefs 2.5.1
- m5unified
- mqtt
- newremoteswitch 8eb980e
- nimble-arduino 2.5.0
- nimbleota 0.2.0
- onewire GPIO-fix
- picomqtt 1.1.1
- rc-switch 98537e9
- rfm69 2e915ea
- rtl-433-esp 0.6.2
- sfe-bmp180 efac46b
- smartrc-cc1101-driver-lib 3.0.2
- somfy-remote-lib 0.3.0
- sparkfun-bme280 2.0.4
- sparkfun-htu21d-humidity-and-temperature-sensor-breakout 1.1.3
- sparkfun-shtc3-arduino-library 671ef7e
- spiffs
- spiflash 9c0c2b9
- tinycbor
- tinyusb
- tlsf
- unity
- uzlib 2.9.5
- weatherstationdatarx 0.3.1
- wifimanager 1ac24f4
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.