Product
riot os riot
41 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-27703
CVE-2026-25139
CVE-2026-22214
CVE-2026-22213
CVE-2025-66647
CVE-2025-66646
CVE-2025-53888
CVE-2024-53980
CVE-2024-52802
CVE-2024-32018
CVE-2024-32017
CVE-2024-31225
CVE-2023-33975
CVE-2023-33974
CVE-2023-33973
CVE-2023-24826
CVE-2023-24825
CVE-2023-24817
CVE-2023-24823
CVE-2023-24822
CVE-2023-24821
CVE-2023-24820
CVE-2023-24819
CVE-2023-24818
CVE-2021-27427
CVE-2021-41061
CVE-2021-31664
CVE-2021-31663
CVE-2021-31662
CVE-2021-31661
CVE-2021-31660
CVE-2021-27698
CVE-2021-27697
CVE-2021-27357
CVE-2020-15350
CVE-2019-17389
CVE-2019-16754
CVE-2019-15702
CVE-2019-15134
CVE-2019-1000006
CVE-2017-8289
<= 2026.01
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices an
<= 2025.10
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices an
< 2025.10
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility du
< 2025.10
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility
< 2025.10
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices an
< 2025.10
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices an
<= 2025.04
RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with
assert() c<= 2024.07
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices an
<= 2024.04
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function
_parse_advertise, l<= 2024.01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit
<= 2024.01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit
< 2024.01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit
<= 2023.01
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
<= 2023.01
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
<= 2023.01
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
< 2023.04
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
< 2023.04
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
< 2023.04
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN fr
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
< 2022.10
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPA
all versions
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitra
all versions
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption b
all versions
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to o
all versions
RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to o
all versions
RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to o
all versions
RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to ob
all versions
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to o
all versions
RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _par
all versions
RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_va
all versions
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.
all versions
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation f
all versions
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The re
all versions
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to cra
<= 2019.07
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowin
<= 2019.07
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory avail
>= 2017.04 and < 2018.10.1
RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, a
<= 2017.01
Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT pri