Gpsd is a narrowly scoped positioning daemon that translates GPS receiver protocols into a standard interface, widely embedded in location-aware applications and embedded systems across automotive, IoT, and navigation platforms. Its observed vulnerability surface clusters around memory-safety and input-parsing issues—including integer underflow, heap and stack buffer overflows, and improper input validation—reflecting the low-level protocol handling and C implementation that characterize parsing-heavy daemons. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gpsd Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58459CRITICAL gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execut | Jul 9, 2026 | 9.6 | 40 | NO | NO |
CVE-2025-67268CRITICAL gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 | Jan 2, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-67269HIGH An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing | Jan 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2018-17937HIGH gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary cod | Mar 13, 2019 | 8.8 | 29 | NO | NO |
CVE-2023-43628HIGH An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacke | Dec 5, 2023 | 7.5 | 23 | NO | NO |
CVE-2013-2038MEDIUM The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malform | Feb 6, 2014 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gpsd Project.
Media articles that mention a CVE ID that affects a product developed by Gpsd Project — matched by CVE ID, not by vendor name.