Known Vulnerabilities for products from Zephyrproject

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Zephyrproject".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-13351 json Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number o... Not Provided 2026-06-25 2026-07-06
CVE-2026-10773 json The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char *... Not Provided 2026-08-01 2026-08-07
CVE-2026-10686 json Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branc... Not Provided 2026-07-31 2026-08-07
CVE-2026-10685 json The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the ... Not Provided 2026-07-31 2026-08-07
CVE-2026-10680 json The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2... Not Provided 2026-07-21 2026-07-30
CVE-2026-10679 json The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->freq... Not Provided 2026-07-21 2026-07-30
CVE-2026-10678 json The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes fr... Not Provided 2026-07-21 2026-07-30
CVE-2026-10677 json The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_po... Not Provided 2026-07-21 2026-07-30
CVE-2026-10675 json In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provi... Not Provided 2026-07-21 2026-07-30
CVE-2026-10674 json The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called L... Not Provided 2026-07-21 2026-07-30
CVE-2026-10672 json subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, siz... Not Provided 2026-07-14 2026-08-06
CVE-2026-10670 json The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thr... Not Provided 2026-07-14 2026-08-06
CVE-2026-10669 json On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the ar... Not Provided 2026-07-14 2026-08-06
CVE-2026-10668 json The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage uncon... Not Provided 2026-07-12 2026-07-16
CVE-2026-10667 json Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked... Not Provided 2026-07-12 2026-07-16
CVE-2026-10666 json parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port... Not Provided 2026-07-12 2026-07-17
CVE-2026-10665 json In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound tr... Not Provided 2026-07-12 2026-07-16
CVE-2026-10664 json The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi... Not Provided 2026-07-12 2026-07-16
CVE-2026-10663 json In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) fre... Not Provided 2026-07-12 2026-07-16
CVE-2026-10659 json The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a ... Not Provided 2026-07-07 2026-07-14

Known software with vulnerabilities from Zephyrproject

Type Vendor Product Version
ApplicationZephyrprojectZephyr1.0.0
Operating
System
ZephyrprojectZephyr1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report