Raspberry Pi OS — CVE reports

4 image releases scanned · cutoff 2026-02-08 · generated 2026-08-10 07:46 UTC · powered by grype · source on GitHub
One row per raspios_* variant — the most recent published release of each, scanned both as-released and after a simulated apt full-upgrade against today's apt archive state. Top-risk is the highest grype risk score across distinct CVEs; background colour bands at 1, 10, and 50. Debian, not Raspbian counts CVEs whose fix is in the Debian archive but not yet rebuilt into the Raspbian archive (so apt upgrade won't fix them) — the armhf build-server backlog, always 0 for arm64, which is built straight from Debian. Sort by any column header.
Variant Released As released After apt full-upgrade (simulated) Report
CVEs Critical KEV Top risk Debian, not Raspbian CVEs Critical KEV Top risk