{
  "project": "OpenThread Border Router",
  "repo_url": "https://github.com/openthread/ot-br-posix",
  "description": "OpenThread's border router for POSIX systems.",
  "release": {
    "filename": "oss-openthread__ot-br-posix.cdx.json",
    "analysed_at": "2026-10-11T07:42:36.596Z"
  },
  "computed_at": "2026-10-11T13:04:07.036Z",
  "summary": {
    "fix": 2,
    "look": 1,
    "clear": 0,
    "unwatched": 1,
    "missed_by_nvd_scanners": 3
  },
  "components": 4,
  "fix": [
    {
      "name": "cpp-httplib",
      "version": "0.19.0",
      "action": "Upgrade to 0.51.0 or later",
      "vulns": [
        {
          "id": "CVE-2025-66570",
          "title": "Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)",
          "severity": "critical",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xm2j-vfr9-mg9m",
            "https://www.cve.org/CVERecord?id=CVE-2025-66570"
          ]
        },
        {
          "id": "CVE-2026-21428",
          "title": "CRLF injection in http headers",
          "severity": "critical",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-wpc6-j37r-jcx7",
            "https://www.cve.org/CVERecord?id=CVE-2026-21428"
          ]
        },
        {
          "id": "CVE-2026-102944",
          "title": "Cookie header leaked on cross-origin redirect",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-22mf-w2v3-r2jv",
            "https://www.cve.org/CVERecord?id=CVE-2026-102944"
          ]
        },
        {
          "id": "CVE-2025-46728",
          "title": "Unbounded Memory Allocation in Chunked/No-Length Requests",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-px83-72rx-v57c",
            "https://www.cve.org/CVERecord?id=CVE-2025-46728"
          ]
        },
        {
          "id": "CVE-2025-53629",
          "title": "Persistency of Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w",
            "https://www.cve.org/CVERecord?id=CVE-2025-53629"
          ]
        },
        {
          "id": "CVE-2026-22776",
          "title": "Denial of service (DOS) using zip bomb",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43q",
            "https://www.cve.org/CVERecord?id=CVE-2026-22776"
          ]
        },
        {
          "id": "CVE-2026-28435",
          "title": "Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xvfx-w463-6fpp",
            "https://www.cve.org/CVERecord?id=CVE-2026-28435"
          ]
        },
        {
          "id": "CVE-2026-31870",
          "title": "Remote Process Crash via Malformed Content-Length Response Header",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-jpxx",
            "https://www.cve.org/CVERecord?id=CVE-2026-31870"
          ]
        },
        {
          "id": "CVE-2026-32627",
          "title": "Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-c3h8-fqq4-xm4g",
            "https://www.cve.org/CVERecord?id=CVE-2026-32627"
          ]
        },
        {
          "id": "CVE-2026-33745",
          "title": "cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-6hrp-7fq9-3qv2",
            "https://www.cve.org/CVERecord?id=CVE-2026-33745"
          ]
        },
        {
          "id": "CVE-2026-45372",
          "title": "HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4m",
            "https://www.cve.org/CVERecord?id=CVE-2026-45372"
          ]
        },
        {
          "id": "CVE-2026-46527",
          "title": "cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash",
          "severity": "high",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-hg3g-vrg8-578g",
            "https://www.cve.org/CVERecord?id=CVE-2026-46527"
          ]
        },
        {
          "id": "CVE-2025-53628",
          "title": "HTTP Header Smuggling due to insecure trailers merge",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw",
            "https://www.cve.org/CVERecord?id=CVE-2025-53628"
          ]
        },
        {
          "id": "CVE-2025-66577",
          "title": "Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust ",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-gfpf-r66f-5mh2",
            "https://www.cve.org/CVERecord?id=CVE-2025-66577"
          ]
        },
        {
          "id": "CVE-2026-28434",
          "title": "Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8mpw-r4gc-xm7q",
            "https://www.cve.org/CVERecord?id=CVE-2026-28434"
          ]
        },
        {
          "id": "CVE-2026-29076",
          "title": "Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qq6v-r583-3h69",
            "https://www.cve.org/CVERecord?id=CVE-2026-29076"
          ]
        },
        {
          "id": "CVE-2026-34441",
          "title": "HTTP Request Smuggling via Unconsumed GET Request Body",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-jv63-rm9j-6jwc",
            "https://www.cve.org/CVERecord?id=CVE-2026-34441"
          ]
        },
        {
          "id": "CVE-2026-45352",
          "title": "DoS: Negative chunk-size in chunked Transfer-Encoding",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h6wq-j5mv-f3q8",
            "https://www.cve.org/CVERecord?id=CVE-2026-45352"
          ]
        },
        {
          "id": "CVE-2026-77341",
          "title": "CRLF injection via unvalidated HTTP trailer headers in chunked response writing",
          "severity": "medium",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-2r2h-jc8w-w66c",
            "https://www.cve.org/CVERecord?id=CVE-2026-77341"
          ]
        },
        {
          "id": "CVE-2026-103930",
          "title": "cpp-httplib open_stream serializes CRLF in request target into HTTP request line",
          "severity": "low",
          "vendor": "cpp-httplib",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-vq69-f637-8fhr",
            "https://www.cve.org/CVERecord?id=CVE-2026-103930"
          ]
        }
      ]
    },
    {
      "name": "cjson",
      "version": "1.7.13..1.7.14",
      "action": "Upgrade to 1.7.18 or later",
      "vulns": [
        {
          "id": "CVE-2023-53154",
          "title": "parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {\"1\":1, with no trailing newline if cJSON_Pars",
          "severity": "low",
          "vendor": null,
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2023-53154",
            "https://www.cve.org/CVERecord?id=CVE-2023-53154"
          ]
        },
        {
          "id": "CVE-2025-57052",
          "title": null,
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2025-57052"
          ]
        },
        {
          "id": "CVE-2026-29036",
          "title": "cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-29036"
          ]
        },
        {
          "id": "CVE-2026-67215",
          "title": "cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-67215"
          ]
        },
        {
          "id": "CVE-2026-67216",
          "title": "cJSON cJSON_Compare Exponential Complexity Denial of Service",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-67216"
          ]
        },
        {
          "id": "CVE-2026-67217",
          "title": "cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-67217"
          ]
        },
        {
          "id": "CVE-2026-87933",
          "title": "DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-87933"
          ]
        }
      ]
    }
  ],
  "look": [
    {
      "name": "openthread",
      "version": "2026.09.0..2026.10.0",
      "action": "Version numbers can't settle this. Have a look.",
      "vulns": [
        {
          "id": "CVE-2023-2626",
          "title": "Missing Key ID Mode validation when processing 6LoWPAN frames",
          "severity": "high",
          "vendor": "openthread",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/openthread/openthread/security/advisories/GHSA-vr3r-363g-72j9",
            "https://www.cve.org/CVERecord?id=CVE-2023-2626"
          ]
        }
      ]
    }
  ],
  "unwatched": [
    {
      "name": "ot-br-posix",
      "version": "v2026.10.0"
    }
  ]
}