P11 Kit Project maintains a focused cryptographic abstraction library that enables applications to access PKCS#11 hardware security modules and smart cards, positioning it as a critical intermediary in the security infrastructure of many Linux distributions and applications. The vulnerability surface is narrow in scope, centered on the library itself, though defenders should recognize that flaws here can propagate broadly across any product that depends on this library for HSM or certificate handling. Current exposure counts and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by P11 Kit Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2100HIGH A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mech | Mar 26, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-13757MEDIUM A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive c | Jun 29, 2026 | 6.2 | 32 | NO | NO |
CVE-2020-29363HIGH An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the clien | Dec 16, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-29361HIGH An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list comm | Dec 16, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-29362MEDIUM An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the c | Dec 16, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by P11 Kit Project.
Media articles that mention a CVE ID that affects a product developed by P11 Kit Project — matched by CVE ID, not by vendor name.