Open-source firmware report

PX4 Autopilot

Flight control software for drones and other unmanned vehicles.

github.com/PX4/PX4-Autopilot · 24 components read from oss-PX4__PX4-Autopilot.cdx.json (analysed 2026-10-11) · checked against today's advisories 2026-10-11

Vulnerabilities affecting this build

2reported by a scanner that checks NVD
5reported by Firmpath
1only in vendors' own advisories, or not yet in NVD for this version

2 more come from OSV and were not checked against NVD; counted as ours, claimed for neither.

1to upgrade
1to look at
0clear
22no advisory source

To upgrade

A published vulnerability affects the version this build uses.

cyclonedds 314887ca403c2fb0a0316add22672102936ed36c Listed for this exact version. Open the CVEs to find the fix.5 vulnerabilities · an NVD scanner reports 2
  • CVE-2024-10838 cyclonedds missed by NVD scannershigh
    Integer Underflow in DDS_Security_Deserialize_ methods may lead to OOB read
  • CVE-2021-38441 medium
    Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t
  • CVE-2021-38443 medium
    Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar
  • OSV-2023-273 OSV
    Heap-buffer-overflow in add_complete_typeobj
  • OSV-2023-556 OSV
    Heap-buffer-overflow in xt_valid_enum_values

To look at

Version numbers cannot settle these: usually a vendor's fork that may already carry the fix.

libtomcrypt 673f5ce29015a9bba3c96792920a10601b5b0718 A vendor fork: check whether it carries the fixes4 vulnerabilities · an NVD scanner reports 4
  • CVE-2019-17362 critical
    In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detec
  • CVE-2016-6129 high
    The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate t
  • CVE-2005-1600 high
    A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows atta
  • CVE-2018-12437 medium
    LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N

No advisory source

No vendor advisory, NVD or OSV record has ever named these. That is not the same as safe: nobody is publishing about them.

How this was made, and what it is not

We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.

It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.