Dropbear
3 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dropbear, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Dropbear CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 3 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium2
- Low1
Latest CVEs
The 3 most recently published vulnerabilities affecting Dropbear.
- CVE-2026-3706mkj Dropbear S Range Check curve25519.c unpackneg signature verification3.7
- CVE-2025-14282Dropbear: privilege escalation via unix domain socket forwardings5.4
- CVE-2017-2659It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly ...5.3
Product grouping is registry-driven, with AI assist and human review. How it works