CVE Tools

Busybox

48 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Busybox, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Busybox CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Busybox CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-042
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-074
2026-080
2026-090

Severity

How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical510%
  • High2144%
  • Medium1838%
  • Low48%

Latest CVEs

The 15 most recently published vulnerabilities affecting Busybox.

  1. CVE-2026-38753A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.4.9
  2. CVE-2026-38752A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.2.9
  3. CVE-2026-38755A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.2.9
  4. CVE-2026-38754A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.5.1
  5. CVE-2025-60876BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to...6.5
  6. CVE-2025-12220Busybox 1.31.1 - Multiple Known Vulnerabilities9.8
  7. CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.3.2
  8. CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) ...2.5
  9. CVE-2023-42363A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.5.5
  10. CVE-2023-42366A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.5.5
  11. CVE-2023-42364A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.5.5
  12. CVE-2023-42365A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.5.5
  13. CVE-2023-39810An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.7.8
  14. CVE-2022-48174There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.9.8
  15. CVE-2022-30065A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store