We use some essential cookies to make our website work.

We use optional cookies, as detailed in our cookie policy, to remember your settings and understand how you use our website.

Security

Raspberry Pi designs computers, silicon, boot firmware, and the software that runs on them. This page explains how to report a security vulnerability in any of our products and what happens after you do. It also lists the advisories we have published for issues we have fixed.

Reporting a vulnerability

Email [email protected]. Our contact details are also published in a machine-readable format at /.well-known/security.txt.

To help us triage your report quickly, please include:

What to expect from us

What is in scope

What is out of scope

Bug bounty programmes

We occasionally run targeted bug bounty programmes and hacking challenges for specific products. Reports made outside of a running programme are not eligible for a reward, but we still want to hear about them and will credit you in the acknowledgements below.

Currently open:

Our RP2350 Hacking Challenge at DEF CON 2024 has now closed.

Reports we will not action

We will close reports that:

Security advisories

We publish advisories here for vulnerabilities we have fixed in our products. Product change notices (PCNs) and compliance documentation are published on the Product Information Portal.

CVE-2026-13199: Insufficient entropy in Raspberry Pi 5’s boot firmware

Affects Raspberry Pi 5 and Raspberry Pi Compute Module 5 running rpi-eeprom before 28.22-1. The boot firmware supplied predictable kaslr-seed and rng-seed values to the kernel, weakening kernel address space layout randomisation.

Fixed in rpi-eeprom 28.22-1, which ships the pieeprom-2026-05-26 firmware release. Update your Raspberry Pi and reboot to apply it.

Full record: CVE-2026-13199 on NVD. Reported by Nozomi Networks Labs, fixed in rpi-eeprom#841.

Raspberry Pi OS CVE list

We scan Raspberry Pi OS every day using Syft and Grype to find publicly known security vulnerabilities from a range of software sources. You can view our current list of known vulnerabilities.

The vulnerability databases these tools rely on change daily, so our scans may occasionally miss an issue. Even so, this list should give you a good understanding of the current security state of our images.

Securing your Raspberry Pi

Please see our security documentation for details.

Acknowledgements

We would like to thank the following security researchers for reporting and helping resolve security vulnerabilities: