OpenThread Border Router
OpenThread's border router for POSIX systems.
Vulnerabilities affecting this build
To upgrade
cpp-httplib 0.19.0 Upgrade to 0.51.0 or later20 vulnerabilities · an NVD scanner reports 17
- CVE-2025-66570 cpp-httplib critical
Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
- CVE-2026-21428 cpp-httplib critical
CRLF injection in http headers
- CVE-2026-102944 cpp-httplib missed by NVD scannershigh
Cookie header leaked on cross-origin redirect
- CVE-2025-46728 cpp-httplib high
Unbounded Memory Allocation in Chunked/No-Length Requests
- CVE-2025-53629 cpp-httplib high
Persistency of Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability
- CVE-2026-22776 cpp-httplib high
Denial of service (DOS) using zip bomb
- CVE-2026-28435 cpp-httplib high
Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib
- CVE-2026-31870 cpp-httplib high
Remote Process Crash via Malformed Content-Length Response Header
- CVE-2026-32627 cpp-httplib high
Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy
- CVE-2026-33745 cpp-httplib high
cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect
- CVE-2026-45372 cpp-httplib high
HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
- CVE-2026-46527 cpp-httplib high
cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash
- CVE-2025-53628 cpp-httplib medium
HTTP Header Smuggling due to insecure trailers merge
- CVE-2025-66577 cpp-httplib medium
Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust
- CVE-2026-28434 cpp-httplib medium
Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header
- CVE-2026-29076 cpp-httplib medium
Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing
- CVE-2026-34441 cpp-httplib medium
HTTP Request Smuggling via Unconsumed GET Request Body
- CVE-2026-45352 cpp-httplib medium
DoS: Negative chunk-size in chunked Transfer-Encoding
- CVE-2026-77341 cpp-httplib missed by NVD scannersmedium
CRLF injection via unvalidated HTTP trailer headers in chunked response writing
- CVE-2026-103930 cpp-httplib missed by NVD scannerslow
cpp-httplib open_stream serializes CRLF in request target into HTTP request line
cjson 1.7.13..1.7.14 Upgrade to 1.7.18 or later7 vulnerabilities · an NVD scanner reports 1
- CVE-2023-53154 low
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars
- CVE-2025-57052 OSV
- CVE-2026-29036 OSV
cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
- CVE-2026-67215 OSV
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
- CVE-2026-67216 OSV
cJSON cJSON_Compare Exponential Complexity Denial of Service
- CVE-2026-67217 OSV
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
- CVE-2026-87933 OSV
DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
To look at
openthread 2026.09.0..2026.10.0 Version numbers can't settle this. Have a look.1 vulnerability · an NVD scanner reports 0
- CVE-2023-2626 openthread missed by NVD scannershigh
Missing Key ID Mode validation when processing 6LoWPAN frames
No advisory source
- ot-br-posix v2026.10.0
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.