The OpenSC Project maintains a cryptographic middleware library that provides access to smart cards and hardware security tokens across multiple platforms, a narrow product scope but one embedded in identity and authentication infrastructure where supply-chain reach matters substantially. The vulnerability footprint concentrates in a single, widely used implementation and recurs through a consistent pattern of memory-safety issues: buffer overflows, out-of-bounds reads and writes, and double-free conditions that are characteristic of C-based cryptographic parsers handling untrusted card data. These weakness classes reflect the low-level nature of smart-card communication and the parsing complexity inherent to supporting multiple card standards and protocols. Defenders should inventory products and systems that link this library, as remediation typically depends on downstream vendors rebuilding and shipping updates; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensc Project over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40528HIGH OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attacke | May 29, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-40510MEDIUM OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically presen | May 29, 2026 | 6.8 | 27 | NO | NO |
CVE-2025-66037MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-boun | Mar 30, 2026 | 6.8 | 25 | NO | NO |
CVE-2025-49010MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c | Mar 30, 2026 | 6.8 | 25 | NO | NO |
CVE-2025-66215MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c | Mar 30, 2026 | 6.8 | 24 | NO | NO |
CVE-2025-66038MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single by | Mar 30, 2026 | 6.8 | 24 | NO | NO |
CVE-2019-20792MEDIUM OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check. | Apr 29, 2020 | 6.8 | 23 | NO | NO |
CVE-2019-16058HIGH An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflo | Sep 6, 2019 | 7.5 | 23 | NO | NO |
CVE-2018-16393MEDIUM Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by at | Sep 3, 2018 | 6.8 | 23 | NO | NO |
CVE-2018-16392MEDIUM Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply | Sep 3, 2018 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensc Project.
Media articles that mention a CVE ID that affects a product developed by Opensc Project — matched by CVE ID, not by vendor name.