Miniupnp Project maintains a narrowly scoped but widely embedded suite of UPnP protocol libraries and daemons used across networking devices, home automation systems, and embedded applications to facilitate device discovery and port mapping. Despite a small product count, the vendor sits prominently in embedded firmware and network infrastructure, where a single vulnerability can propagate to large numbers of devices with long support horizons. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code; the exposure concentrates in core components such as miniupnpd and miniupnpc and recurs through memory-safety weakness classes including out-of-bounds writes and reads, buffer-boundary violations, and NULL-pointer dereferences that are characteristic of C-based protocol parsers. Defenders should prioritize inventory and updates of devices running affected UPnP libraries, particularly those exposed to untrusted networks, since remediation often depends on manufacturer firmware releases rather than direct patching. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniupnp Project over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0230HIGH Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary c | Jan 31, 2013 | 10.0 | 84 | NO | YES |
CVE-2013-0229HIGH The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafte | Jan 31, 2013 | 7.8 | 82 | NO | YES |
CVE-2017-8798CRITICAL Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. | May 11, 2017 | 9.8 | 56 | NO | YES |
CVE-2026-5720CRITICAL miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a | Apr 17, 2026 | 9.1 | 31 | NO | NO |
CVE-2018-11576CRITICAL ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. | May 31, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-11575CRITICAL ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg. | May 31, 2018 | 9.8 | 28 | NO | NO |
CVE-2021-36530HIGH ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffer without checking the boundary. | Aug 27, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-20219HIGH ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. | Jan 2, 2020 | 8.8 | 27 | NO | NO |
CVE-2018-10717HIGH The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service | May 3, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-36531HIGH ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer without checking the boundary. | Aug 27, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniupnp Project.
Media articles that mention a CVE ID that affects a product developed by Miniupnp Project — matched by CVE ID, not by vendor name.