Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Zephyrproject

72 known vulnerabilities

2
CRITICAL
23
HIGH
39
MEDIUM
8
LOW

Top Products

zephyr 72
72 CVEs · Page 2/2
7.1
CVE-2026-10641

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont

4.2
CVE-2026-10640

Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_

4.8
CVE-2026-10639

In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply

5.9
CVE-2026-10638

subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data

5.9
CVE-2026-10637

subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned s

3.7
CVE-2026-10636

In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac

6.3
CVE-2026-10635

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain

4.8
CVE-2026-10634

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S

7.6
CVE-2026-5068

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD

9.8
CVE-2026-5067

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi

6.3
CVE-2026-5066

A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/

6.3
CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati

6.1
CVE-2026-5071

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using on

6.5
CVE-2026-5072

A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti

6.1
CVE-2026-1681

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi

5.3
CVE-2026-1677

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable

6.4
CVE-2026-5590

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been re

7.3
CVE-2026-1679

The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; ove

6.1
CVE-2026-4179

Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.

3.8
CVE-2026-0849

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver

9.4
CVE-2026-1678

dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac

4.6
CVE-2026-20435

In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor

Frequently Asked Questions

How many CVEs affect Zephyrproject?

Zephyrproject has 72 CVE records in our database, including 2 critical and 23 high severity vulnerabilities.

What are the most severe Zephyrproject vulnerabilities?

Zephyrproject has 2 critical severity (CVSS 9.0+) and 23 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Zephyrproject vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zephyrproject products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Zephyrproject Vulnerabilities

CyberStrike scans your infrastructure for Zephyrproject vulnerabilities and provides real-time remediation guidance.

Get Started