VYPR

UpdateHub

by Zephyrproject Rtos

Source repositories

CVEs (2)

  • CVE-2026-11810HigAug 10, 2026
    risk 0.42cvss 7.5epss 0.00

    The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length…

  • CVE-2020-10059MedMay 11, 2020
    risk 0.00cvss 4.8epss 0.01

    The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects:…