Raspberry Pi designs computers, silicon, boot firmware, and the software that runs on them. This page explains how to report a security vulnerability in any of our products and what happens after you do. It also lists the advisories we have published for issues we have fixed.
Email [email protected]. Our contact details are also published in a machine-readable format at /.well-known/security.txt.
To help us triage your report quickly, please include:
We occasionally run targeted bug bounty programmes and hacking challenges for specific products. Reports made outside of a running programme are not eligible for a reward, but we still want to hear about them and will credit you in the acknowledgements below.
Currently open:
Our RP2350 Hacking Challenge at DEF CON 2024 has now closed.
We will close reports that:
We publish advisories here for vulnerabilities we have fixed in our products. Product change notices (PCNs) and compliance documentation are published on the Product Information Portal.
Affects Raspberry Pi 5 and Raspberry Pi Compute Module 5 running rpi-eeprom before 28.22-1. The boot firmware supplied predictable kaslr-seed and rng-seed values to the kernel, weakening kernel address space layout randomisation.
Fixed in rpi-eeprom 28.22-1, which ships the pieeprom-2026-05-26 firmware release. Update your Raspberry Pi and reboot to apply it.
Full record: CVE-2026-13199 on NVD. Reported by Nozomi Networks Labs, fixed in rpi-eeprom#841.
We scan Raspberry Pi OS every day using Syft and Grype to find publicly known security vulnerabilities from a range of software sources. You can view our current list of known vulnerabilities.
The vulnerability databases these tools rely on change daily, so our scans may occasionally miss an issue. Even so, this list should give you a good understanding of the current security state of our images.
Please see our security documentation for details.
We would like to thank the following security researchers for reporting and helping resolve security vulnerabilities: