Open-source firmware report

OpenThread Border Router

OpenThread's border router for POSIX systems.

github.com/openthread/ot-br-posix · 4 components read from oss-openthread__ot-br-posix.cdx.json (analysed 2026-10-11) · checked against today's advisories 2026-10-11

Vulnerabilities affecting this build

18reported by a scanner that checks NVD
27reported by Firmpath
3only in vendors' own advisories, or not yet in NVD for this version

6 more come from OSV and were not checked against NVD; counted as ours, claimed for neither.

2to upgrade
1to look at
0clear
1no advisory source

To upgrade

A published vulnerability affects the version this build uses.

cpp-httplib 0.19.0 Upgrade to 0.51.0 or later20 vulnerabilities · an NVD scanner reports 17
  • CVE-2025-66570 cpp-httplib critical
    Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
  • CVE-2026-21428 cpp-httplib critical
    CRLF injection in http headers
  • CVE-2026-102944 cpp-httplib missed by NVD scannershigh
    Cookie header leaked on cross-origin redirect
  • CVE-2025-46728 cpp-httplib high
    Unbounded Memory Allocation in Chunked/No-Length Requests
  • CVE-2025-53629 cpp-httplib high
    Persistency of Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability
  • CVE-2026-22776 cpp-httplib high
    Denial of service (DOS) using zip bomb
  • CVE-2026-28435 cpp-httplib high
    Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib
  • CVE-2026-31870 cpp-httplib high
    Remote Process Crash via Malformed Content-Length Response Header
  • CVE-2026-32627 cpp-httplib high
    Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy
  • CVE-2026-33745 cpp-httplib high
    cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect
  • CVE-2026-45372 cpp-httplib high
    HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
  • CVE-2026-46527 cpp-httplib high
    cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash
  • CVE-2025-53628 cpp-httplib medium
    HTTP Header Smuggling due to insecure trailers merge
  • CVE-2025-66577 cpp-httplib medium
    Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust
  • CVE-2026-28434 cpp-httplib medium
    Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header
  • CVE-2026-29076 cpp-httplib medium
    Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing
  • CVE-2026-34441 cpp-httplib medium
    HTTP Request Smuggling via Unconsumed GET Request Body
  • CVE-2026-45352 cpp-httplib medium
    DoS: Negative chunk-size in chunked Transfer-Encoding
  • CVE-2026-77341 cpp-httplib missed by NVD scannersmedium
    CRLF injection via unvalidated HTTP trailer headers in chunked response writing
  • CVE-2026-103930 cpp-httplib missed by NVD scannerslow
    cpp-httplib open_stream serializes CRLF in request target into HTTP request line
cjson 1.7.13..1.7.14 Upgrade to 1.7.18 or later7 vulnerabilities · an NVD scanner reports 1
  • CVE-2023-53154 low
    parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars
  • CVE-2025-57052 OSV
  • CVE-2026-29036 OSV
    cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
  • CVE-2026-67215 OSV
    cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
  • CVE-2026-67216 OSV
    cJSON cJSON_Compare Exponential Complexity Denial of Service
  • CVE-2026-67217 OSV
    cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
  • CVE-2026-87933 OSV
    DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free

To look at

Version numbers cannot settle these: usually a vendor's fork that may already carry the fix.

openthread 2026.09.0..2026.10.0 Version numbers can't settle this. Have a look.1 vulnerability · an NVD scanner reports 0
  • CVE-2023-2626 openthread missed by NVD scannershigh
    Missing Key ID Mode validation when processing 6LoWPAN frames

No advisory source

No vendor advisory, NVD or OSV record has ever named these. That is not the same as safe: nobody is publishing about them.

How this was made, and what it is not

We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.

It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.