Gerbv is a niche open-source Gerber file viewer and editor used in PCB design and manufacturing workflows, maintaining a focused product footprint around its core parsing and visualization engine. Vulnerabilities affecting the project skew strongly toward critical-severity outcomes and cluster around memory-safety issues including out-of-bounds reads and writes, buffer-boundary violations, and improper exception handling—weaknesses characteristic of C-based file parsers processing untrusted design data. Defenders relying on this tool for production PCB workflows should prioritize updates to close memory-corruption gaps; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gerbv Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40394CRITICAL An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv | Dec 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-40393CRITICAL An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv | Dec 22, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-40391CRITICAL An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 7149 | Nov 19, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-40401HIGH A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-cra | Feb 4, 2022 | 8.6 | 28 | NO | NO |
CVE-2021-40402HIGH An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 | Apr 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-40400HIGH An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (c | Apr 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-40403MEDIUM An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-cr | Feb 4, 2022 | 6.3 | 22 | NO | NO |
CVE-2023-4508MEDIUM A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file. | Aug 24, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gerbv Project.
Media articles that mention a CVE ID that affects a product developed by Gerbv Project — matched by CVE ID, not by vendor name.