Agronholm develops the cbor2 library, a Python implementation of CBOR (Concise Binary Object Representation) serialization used for compact data encoding in embedded and IoT applications. Its vulnerability profile centers on encoding and data-handling flaws including buffer overflows, improper information removal, integer underflow conditions, and uncontrolled recursion—weaknesses characteristic of parsers processing untrusted binary input. Current exploitation activity, severity assessment, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agronholm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68131HIGH cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDec | Dec 31, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-26209HIGH cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions prior to 5.9.0 are vulnerable to a Denial of Service (DoS) a | Mar 23, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-64076HIGH Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Lea | Nov 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-26134HIGH cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an a | Feb 19, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agronholm.
Media articles that mention a CVE ID that affects a product developed by Agronholm — matched by CVE ID, not by vendor name.