Busybox is a lightweight, single-product utility suite widely embedded in embedded systems, IoT devices, and Linux distributions where space and resource constraints demand minimal footprints. Despite its narrow product scope, the vendor sits deep in the embedded and mobile supply chain, making its vulnerabilities relevant across thousands of downstream deployments. The recurring vulnerability classes—use-after-free, NULL-pointer dereferences, out-of-bounds reads, improper input validation, and path-traversal flaws—reflect the C-based implementation and the parsing complexity inherent to a compact multipurpose utility toolkit. A meaningful share of Busybox's disclosures reach serious severity, and defenders should treat updates to this component as a supply-chain priority given its pervasive embedding in firmware and containerized environments. Current exploitation activity and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Busybox over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000517CRITICAL BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffe | Jun 26, 2018 | 9.8 | 45 | NO | NO |
CVE-2016-2148CRITICAL Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. | Feb 9, 2017 | 9.8 | 45 | NO | NO |
CVE-2026-38755HIGH A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | Jul 15, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-38752HIGH A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-38754HIGH A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-38753HIGH A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | Jul 15, 2026 | 7.5 | 32 | NO | NO |
CVE-2021-42377CRITICAL An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishan | Nov 15, 2021 | 9.8 | 31 | NO | NO |
CVE-2017-16544HIGH In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitiz | Nov 20, 2017 | 8.8 | 31 | NO | NO |
CVE-2022-48174CRITICAL There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitra | Aug 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-28391HIGH BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attack | Apr 3, 2022 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Busybox.
Media articles that mention a CVE ID that affects a product developed by Busybox — matched by CVE ID, not by vendor name.