Skip to content

Security: bacnet-stack/bacnet-stack

SECURITY.md

Security Policy

Supported Versions

The following versions of the BACnet Stack C library are currently being supported with security updates.

Version Supported
1.4.x βœ…
1.3.x βœ…
1.2.x βœ…
1.1.x βœ…
1.0.x βœ…
0.9.x ❌
0.8.x βœ…
0.7.x ❌
< 0.6.x ❌

Coordinated Vulnerability Disclosure

From time to time a vulnerability is disclosed to CVE and a record is created to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

Here are the known CVE records:

CVE-2026-26264 - WriteProperty decoding length underflow leads to OOB read and crash GHSA-phjh-v45p-gmjj

CVE-2026-21870 - Off-by-one Stack-based Buffer Overflow in tokenizer_string GHSA-pc83-wp6w-93mx

CVE-2026-21878 - Improper Limitation of a Pathname to a Restricted Directory GHSA-p8rx-c26w-545j

CVE-2025-66624 - BACnet-stack MS/TP reply matcher OOB read GHSA-8wgw-5h6x-qgqg

CVE-2023-38341 - Multiple out-of-bounds accesses in bacerror code paths #81

CVE-2023-38340 - Out of bounds accesses in bacnet_npdu_decode #80

CVE-2023-38339 - Out of bounds jump in h_apdu.c:apdu_handler #79

CVE-2019-12480 - Invalid read in bacserv when decoding alarm tags #62

CVE-2018-10238 - Segmentation fault leading to denial of service #61

Reporting a Vulnerability

Please use the "bugs" feature of Sourceforge.net to report a vulnerability, where it will be tracked until it is resolved. https://sourceforge.net/p/bacnet/bugs/

Vulnerabilities can also be reported using "issues" at Github. https://github.com/bacnet-stack/bacnet-stack/issues

Learn more about advisories related to bacnet-stack/bacnet-stack in the GitHub Advisory Database