{"schema_version":1,"title":"Busybox vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Busybox: 7 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88840, was published on 23 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/busybox","json_url":"https://junglewise.ai/threats/vendors/busybox.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/busybox","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":5,"all_time":15,"critical":0,"exploited":0,"last_7_days":7,"last_30_days":7,"last_90_days":11,"last_365_days":15},"latest":[{"cve":"CVE-2026-88840","cvss":5.3,"epss":0.0021,"slug":"cve-2026-88840-busybox-tls-get-client-hello-reads-past-the-end-of-the-input","title":"BusyBox TLS out-of-bounds read in ClientHello parsing","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.79+00:00","url":"https://junglewise.ai/threats/cve-2026-88840-busybox-tls-get-client-hello-reads-past-the-end-of-the-input"},{"cve":"CVE-2026-88839","cvss":6.7,"epss":0.0012,"slug":"cve-2026-88839-busybox-passwd-group-tokenize-references-a-stale-endpoint-pointer","title":"BusyBox passwd/group tokenize() heap pointer out-of-bounds write","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.64+00:00","url":"https://junglewise.ai/threats/cve-2026-88839-busybox-passwd-group-tokenize-references-a-stale-endpoint-pointer"},{"cve":"CVE-2026-88837","cvss":6.5,"epss":0.0023,"slug":"cve-2026-88837-busybox-httpd-treats-yescrypt-y-password-hashes-as-plaintext","title":"BusyBox httpd authentication bypass with yescrypt hashes","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.493+00:00","url":"https://junglewise.ai/threats/cve-2026-88837-busybox-httpd-treats-yescrypt-y-password-hashes-as-plaintext"},{"cve":"CVE-2026-88835","cvss":6.1,"epss":0.0011,"slug":"cve-2026-88835-busybox-dpkg-read-package-field-steps-past-a-nul-terminator-on","title":"BusyBox dpkg read_package_field() out-of-bounds heap read","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.35+00:00","url":"https://junglewise.ai/threats/cve-2026-88835-busybox-dpkg-read-package-field-steps-past-a-nul-terminator-on"},{"cve":"CVE-2026-88831","cvss":5.3,"epss":0.0021,"slug":"cve-2026-88831-busybox-httpd-ip-deny-rules-with-invalid-cidr-prefix-lengths-fail","title":"BusyBox httpd IP deny rules CIDR prefix parsing bypass","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.08+00:00","url":"https://junglewise.ai/threats/cve-2026-88831-busybox-httpd-ip-deny-rules-with-invalid-cidr-prefix-lengths-fail"},{"cve":"CVE-2026-88832","cvss":7.3,"epss":0.0012,"slug":"cve-2026-88832-busybox-romfs-volume-id-parsing-uses-unbounded-strlen-on-attacker","title":"BusyBox romfs volume ID parsing heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:18.573+00:00","url":"https://junglewise.ai/threats/cve-2026-88832-busybox-romfs-volume-id-parsing-uses-unbounded-strlen-on-attacker"},{"cve":"CVE-2026-88830","cvss":7.5,"epss":0.0035,"slug":"cve-2026-88830-a-unit-confusion-in-busybox-tls-montgomery-reduction-buffer","title":"BusyBox TLS heap buffer overflow in Montgomery reduction","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:18.427+00:00","url":"https://junglewise.ai/threats/cve-2026-88830-a-unit-confusion-in-busybox-tls-montgomery-reduction-buffer"},{"cve":"CVE-2026-38755","cvss":0,"slug":"cve-2026-38755-busybox-ash-heap-overflow-in-evalcommand-function","title":"BusyBox ash heap overflow in evalcommand function","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:47.34+00:00","url":"https://junglewise.ai/threats/cve-2026-38755-busybox-ash-heap-overflow-in-evalcommand-function"},{"cve":"CVE-2026-38754","cvss":0,"slug":"cve-2026-38754-busybox-ash-heap-overflow-in-ifsbreakup","title":"BusyBox ash heap overflow in ifsbreakup","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:47.233+00:00","url":"https://junglewise.ai/threats/cve-2026-38754-busybox-ash-heap-overflow-in-ifsbreakup"},{"cve":"CVE-2026-38752","slug":"cve-2026-38752-busybox-stack-overflow-in-awk-evaluate-function","title":"BusyBox stack overflow in AWK evaluate function","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:47.13+00:00","url":"https://junglewise.ai/threats/cve-2026-38752-busybox-stack-overflow-in-awk-evaluate-function"},{"cve":"CVE-2026-38753","slug":"cve-2026-38753-busybox-awk-use-after-free-in-awk-sub","title":"BusyBox AWK use-after-free in awk_sub","severity":"info","exploited":false,"published_at":"2026-07-15T21:16:36.677+00:00","url":"https://junglewise.ai/threats/cve-2026-38753-busybox-awk-use-after-free-in-awk-sub"},{"cve":"CVE-2026-29004","cvss":8.1,"epss":0.0032,"slug":"cve-2026-29004-busybox-heap-buffer-overflow-in-udhcpc6-dns-servers-handler","title":"BusyBox heap buffer overflow in udhcpc6 DNS_SERVERS handler","severity":"high","exploited":false,"published_at":"2026-05-04T18:16:26.523+00:00","url":"https://junglewise.ai/threats/cve-2026-29004-busybox-heap-buffer-overflow-in-udhcpc6-dns-servers-handler"},{"cve":"CVE-2026-26158","cvss":7,"epss":0.0001,"slug":"cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link","title":"BusyBox arbitrary file modification via unvalidated tar link entries","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.607+00:00","url":"https://junglewise.ai/threats/cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link"},{"cve":"CVE-2026-26157","cvss":7,"epss":0.0014,"slug":"cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities","title":"BusyBox path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.4+00:00","url":"https://junglewise.ai/threats/cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2025-60876","cvss":6.5,"epss":0.0005,"slug":"cve-2025-60876-busybox-wget-http-header-injection-via-request-target-splitting","title":"BusyBox wget HTTP header injection via request-target splitting","severity":"medium","exploited":false,"published_at":"2025-11-10T20:15:48.683+00:00","url":"https://junglewise.ai/threats/cve-2025-60876-busybox-wget-http-header-injection-via-request-target-splitting"}],"vendor":{"hub":true,"name":"Busybox","slug":"busybox","homepage":"https://busybox.net/","description":"BusyBox is a software suite that provides several Unix utilities in a single executable file.","url":"https://junglewise.ai/threats/vendors/busybox"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":7}],"most_severe":[{"cve":"CVE-2026-29004","cvss":8.1,"epss":0.0032,"slug":"cve-2026-29004-busybox-heap-buffer-overflow-in-udhcpc6-dns-servers-handler","title":"BusyBox heap buffer overflow in udhcpc6 DNS_SERVERS handler","severity":"high","exploited":false,"published_at":"2026-05-04T18:16:26.523+00:00","url":"https://junglewise.ai/threats/cve-2026-29004-busybox-heap-buffer-overflow-in-udhcpc6-dns-servers-handler"},{"cve":"CVE-2026-88830","cvss":7.5,"epss":0.0035,"slug":"cve-2026-88830-a-unit-confusion-in-busybox-tls-montgomery-reduction-buffer","title":"BusyBox TLS heap buffer overflow in Montgomery reduction","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:18.427+00:00","url":"https://junglewise.ai/threats/cve-2026-88830-a-unit-confusion-in-busybox-tls-montgomery-reduction-buffer"},{"cve":"CVE-2026-88832","cvss":7.3,"epss":0.0012,"slug":"cve-2026-88832-busybox-romfs-volume-id-parsing-uses-unbounded-strlen-on-attacker","title":"BusyBox romfs volume ID parsing heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:18.573+00:00","url":"https://junglewise.ai/threats/cve-2026-88832-busybox-romfs-volume-id-parsing-uses-unbounded-strlen-on-attacker"},{"cve":"CVE-2026-26157","cvss":7,"epss":0.0014,"slug":"cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities","title":"BusyBox path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.4+00:00","url":"https://junglewise.ai/threats/cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2026-26158","cvss":7,"epss":0.0001,"slug":"cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link","title":"BusyBox arbitrary file modification via unvalidated tar link entries","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.607+00:00","url":"https://junglewise.ai/threats/cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link"},{"cve":"CVE-2026-88839","cvss":6.7,"epss":0.0012,"slug":"cve-2026-88839-busybox-passwd-group-tokenize-references-a-stale-endpoint-pointer","title":"BusyBox passwd/group tokenize() heap pointer out-of-bounds write","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.64+00:00","url":"https://junglewise.ai/threats/cve-2026-88839-busybox-passwd-group-tokenize-references-a-stale-endpoint-pointer"},{"cve":"CVE-2026-88837","cvss":6.5,"epss":0.0023,"slug":"cve-2026-88837-busybox-httpd-treats-yescrypt-y-password-hashes-as-plaintext","title":"BusyBox httpd authentication bypass with yescrypt hashes","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.493+00:00","url":"https://junglewise.ai/threats/cve-2026-88837-busybox-httpd-treats-yescrypt-y-password-hashes-as-plaintext"},{"cve":"CVE-2025-60876","cvss":6.5,"epss":0.0005,"slug":"cve-2025-60876-busybox-wget-http-header-injection-via-request-target-splitting","title":"BusyBox wget HTTP header injection via request-target splitting","severity":"medium","exploited":false,"published_at":"2025-11-10T20:15:48.683+00:00","url":"https://junglewise.ai/threats/cve-2025-60876-busybox-wget-http-header-injection-via-request-target-splitting"},{"cve":"CVE-2026-88835","cvss":6.1,"epss":0.0011,"slug":"cve-2026-88835-busybox-dpkg-read-package-field-steps-past-a-nul-terminator-on","title":"BusyBox dpkg read_package_field() out-of-bounds heap read","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.35+00:00","url":"https://junglewise.ai/threats/cve-2026-88835-busybox-dpkg-read-package-field-steps-past-a-nul-terminator-on"},{"cve":"CVE-2026-88840","cvss":5.3,"epss":0.0021,"slug":"cve-2026-88840-busybox-tls-get-client-hello-reads-past-the-end-of-the-input","title":"BusyBox TLS out-of-bounds read in ClientHello parsing","severity":"medium","exploited":false,"published_at":"2026-09-23T18:17:10.79+00:00","url":"https://junglewise.ai/threats/cve-2026-88840-busybox-tls-get-client-hello-reads-past-the-end-of-the-input"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"BusyBox","slug":"busybox","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/busybox"}]}