{
  "project": "Tasmota",
  "repo_url": "https://github.com/arendst/Tasmota",
  "description": "Alternative firmware for ESP32 and ESP8266 smart-home devices.",
  "release": {
    "filename": "oss-arendst__Tasmota.cdx.json",
    "analysed_at": "2026-10-11T06:54:54.610Z"
  },
  "computed_at": "2026-10-11T13:03:57.641Z",
  "summary": {
    "fix": 3,
    "look": 3,
    "clear": 3,
    "unwatched": 15,
    "missed_by_nvd_scanners": 15
  },
  "components": 24,
  "fix": [
    {
      "name": "mbedtls",
      "version": "3.6.6",
      "action": "Upgrade to 3.6.7 or later",
      "vulns": [
        {
          "id": "CVE-2026-50580",
          "title": "Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecdhe-psk-client-buffer-overflow/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50580"
          ]
        },
        {
          "id": "CVE-2026-50579",
          "title": "Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-use-after-free-pkcs7-free-reused-context/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50579"
          ]
        },
        {
          "id": "CVE-2026-50713",
          "title": "Heap corruption with early renegotiation after corrupted record in DTLS",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-heap-corruption-early-renegotiation-corrupted-dtls-record/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50713"
          ]
        },
        {
          "id": "CVE-2026-50584",
          "title": "ChaCha20 counter overflow can reuse keystream",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-chacha20-counter-overflow-keystream-reuse/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50584"
          ]
        },
        {
          "id": "CVE-2026-50587",
          "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-rsa-pkcs1-v15-decryption-timing-side-channel/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50587"
          ]
        },
        {
          "id": "CVE-2026-50640",
          "title": "Ignored TLS 1.3 resumption secret derivation error",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ignored-tls13-resumption-secret-derivation-error/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50640"
          ]
        },
        {
          "id": "CVE-2026-50583",
          "title": "Out-of-bounds read when parsing a zero-length ECC public key",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-zero-length-ecc-public-key-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50583"
          ]
        },
        {
          "id": "CVE-2026-50586",
          "title": "Information disclosure in TLS 1.2 NewSessionTicket",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-newsessionticket-information-disclosure/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50586"
          ]
        },
        {
          "id": "CVE-2026-73096",
          "title": "TLS 1.3 early data integrity failure due to buffered plaintext across key change",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls13-early-data-integrity-failure-key-change/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73096"
          ]
        },
        {
          "id": "CVE-2026-50585",
          "title": "Incomplete context reset in mbedtls_ssl_session_reset()",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ssl-session-reset-incomplete-context-reset/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50585"
          ]
        },
        {
          "id": "CVE-2026-54441",
          "title": "Signature algorithm restrictions not enforced on certificate chain",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-signature-algorithm-restrictions-certificate-chain/",
            "https://www.cve.org/CVERecord?id=CVE-2026-54441"
          ]
        },
        {
          "id": "CVE-2026-73064",
          "title": "A random generator fault can compromise TLS data integrity",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-random-generator-fault-tls-integrity/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73064"
          ]
        },
        {
          "id": "CVE-2025-66442",
          "title": "Compiler-induced constant-time violations",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-66442",
            "https://www.cve.org/CVERecord?id=CVE-2025-66442"
          ]
        },
        {
          "id": "CVE-2026-50588",
          "title": "Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecjpake-serverkeyexchange-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50588"
          ]
        }
      ]
    },
    {
      "name": "nimble",
      "version": "1.6.0",
      "action": "Upgrade to 1.10.0 or later",
      "vulns": [
        {
          "id": "CVE-2026-45815",
          "title": "Remote reachable assertion in ATT Read Multiple Variable Response handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45815",
            "https://www.cve.org/CVERecord?id=CVE-2026-45815"
          ]
        },
        {
          "id": "CVE-2025-52435",
          "title": "Invalid error handling in pause encryption procedure in NimBLE controller",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-52435",
            "https://www.cve.org/CVERecord?id=CVE-2025-52435"
          ]
        },
        {
          "id": "CVE-2024-51569",
          "title": "Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-51569",
            "https://www.cve.org/CVERecord?id=CVE-2024-51569"
          ]
        },
        {
          "id": "CVE-2026-45813",
          "title": "Incorrect data validation in BASS add/modify source operation",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45813",
            "https://www.cve.org/CVERecord?id=CVE-2026-45813"
          ]
        },
        {
          "id": "CVE-2024-24746",
          "title": "Denial of service in NimBLE Bluetooth stack",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-24746",
            "https://www.cve.org/CVERecord?id=CVE-2024-24746"
          ]
        },
        {
          "id": "CVE-2026-45811",
          "title": "Buffer overflow in socket HCI transport",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45811",
            "https://www.cve.org/CVERecord?id=CVE-2026-45811"
          ]
        },
        {
          "id": "CVE-2025-53477",
          "title": "NULL Pointer Dereference in NimBLE host HCI layer",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53477",
            "https://www.cve.org/CVERecord?id=CVE-2025-53477"
          ]
        },
        {
          "id": "CVE-2026-45816",
          "title": "NULL pointer dereference vulnerability in SMP LTK request",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45816",
            "https://www.cve.org/CVERecord?id=CVE-2026-45816"
          ]
        },
        {
          "id": "CVE-2026-45812",
          "title": "OOB Read via sizeof(pointer) in Legacy Advertising Report Handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45812",
            "https://www.cve.org/CVERecord?id=CVE-2026-45812"
          ]
        },
        {
          "id": "CVE-2024-47249",
          "title": "Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-47249",
            "https://www.cve.org/CVERecord?id=CVE-2024-47249"
          ]
        },
        {
          "id": "CVE-2026-46452",
          "title": "Mesh Proxy SAR reassembly unbounded append and unchecked failure",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-46452",
            "https://www.cve.org/CVERecord?id=CVE-2026-46452"
          ]
        },
        {
          "id": "CVE-2025-53470",
          "title": "Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver",
          "severity": "low",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53470",
            "https://www.cve.org/CVERecord?id=CVE-2025-53470"
          ]
        }
      ]
    },
    {
      "name": "esp-idf",
      "version": "5.5.5",
      "action": "Upgrade to 6.1.1 or later",
      "vulns": [
        {
          "id": "CVE-2026-81508",
          "title": "Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/espressif/esp-idf/security/advisories/GHSA-xcpr-5mqp-9qvv",
            "https://www.cve.org/CVERecord?id=CVE-2026-81508"
          ]
        },
        {
          "id": "CVE-2020-26142",
          "title": "Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://www.espressif.com/sites/default/files/advisory_downloads/AR2023-008%20Security%20Advisory%20for%20WLAN%20FragAttacks%20EN.pdf",
            "https://www.cve.org/CVERecord?id=CVE-2020-26142"
          ]
        }
      ]
    }
  ],
  "look": [
    {
      "name": "lwip",
      "version": "2.2.0",
      "action": "A vendor fork: check whether it carries the fixes",
      "vulns": [
        {
          "id": "CVE-2020-22283",
          "title": "Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2020-22283",
            "https://www.cve.org/CVERecord?id=CVE-2020-22283"
          ]
        }
      ]
    },
    {
      "name": "openthread",
      "version": "2026.07.0..",
      "action": "A vendor fork: check whether it carries the fixes",
      "vulns": [
        {
          "id": "CVE-2023-2626",
          "title": "Missing Key ID Mode validation when processing 6LoWPAN frames",
          "severity": "high",
          "vendor": "openthread",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/openthread/openthread/security/advisories/GHSA-vr3r-363g-72j9",
            "https://www.cve.org/CVERecord?id=CVE-2023-2626"
          ]
        }
      ]
    },
    {
      "name": "coex-lib",
      "version": null,
      "action": "Bundled in an SDK with no version of its own. Check the advisories.",
      "vulns": [
        {
          "id": "CVE-2021-26706",
          "title": "Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/200-299/A-00000279.md",
            "https://www.cve.org/CVERecord?id=CVE-2021-26706"
          ]
        }
      ]
    }
  ],
  "unwatched": [
    {
      "name": "cmock",
      "version": "v2.5.2-2-geeecc49ce8af"
    },
    {
      "name": "esp-ble-mesh-lib",
      "version": null
    },
    {
      "name": "esp-phy-lib",
      "version": null
    },
    {
      "name": "esp-thread-lib",
      "version": null
    },
    {
      "name": "esp32-bt-lib",
      "version": null
    },
    {
      "name": "esp32-wifi-lib",
      "version": null
    },
    {
      "name": "esp32c2-bt-lib",
      "version": null
    },
    {
      "name": "esp32c3-bt-lib",
      "version": null
    },
    {
      "name": "esp32c5-bt-lib",
      "version": null
    },
    {
      "name": "esp32c6-bt-lib",
      "version": null
    },
    {
      "name": "esp32h2-bt-lib",
      "version": null
    },
    {
      "name": "mqtt",
      "version": null
    },
    {
      "name": "spiffs",
      "version": "0.2-265-gad902ca"
    },
    {
      "name": "tlsf",
      "version": null
    },
    {
      "name": "unity",
      "version": "v2.6.0-RC1"
    }
  ]
}