Security bulletin 2026-07#

This bulletin lists the critical and high severity vulnerabilities that were fixed for the month of July, 2026.

This bulletin was last updated on July 30th, 2026.

Vulnerability details#

CVE

Reference

Impact

Modules affected

Fixed by

TBD

b/512562473

S

pw_protobuf

ed4e552afe0093c8c70218392a07af77ab6668fd

TBD

b/512562483

DoS

pw_transfer

7c29e52c8b99a8792b7e44f6687930c311f4f78f

How to interpret the table#

  • CVEs are assigned after a fix is released, and may be listed as “TBD” in the interim.

  • If the ‘Reference’ column is “N/A”, the bug report cannot be made public at this time.

  • The ‘Impact’ column uses the following abbreviations:

    Abbreviation

    Definition

    CE

    Potential code execution, including most memory corruptions that affect control flow.

    S

    Spoofing, such as injection of malicious data from what appears to be a valid source

    T

    Tampering, such as modifying state or user data in way that affects device behavior

    ID

    Information disclosure, including memory corruptions such as out-of-bound reads

    DoS

    Denial of service, such as triggering assertions

    N/A

    Classification not available

  • The ‘Fixed by’ column provides the revision that consumers should upgrade to or cherry-pick.

  • The ‘Modules affected’ column lists the primary modules affected. Be aware that other modules may be affected through transitive dependencies.