Raspberry Pi designs silicon, computers, boot firmware, and the software that runs on them. This page explains how to report a security vulnerability in any of it and what happens after you do. It also lists the advisories we have published for issues we have fixed.
Email [email protected]. Our contact details are also published in machine-readable form at /.well-known/security.txt.
To help us triage your report quickly, please include:
We occasionally run targeted bug bounty programmes and hacking challenges against specific products. Reports made outside a running programme are not eligible for a reward, but we still want to hear about them and will credit you in the acknowledgements below.
Currently open:
Our RP2350 Hacking Challenge at DEF CON 2024 has now closed.
We will close reports that describe one of HackerOne’s Core Ineligible Findings, that do not include a detailed step-by-step explanation of how to replicate the issue and demonstrate relevant security impact, or whose root cause is not under our control.
We publish advisories here for vulnerabilities we have fixed in our products. Product change notices and compliance documentation are published on the Product Information Portal.
Affects Raspberry Pi 5 and Compute Module 5 running rpi-eeprom before 28.22-1. The boot firmware supplied predictable kaslr-seed and rng-seed values to the kernel, weakening kernel address space layout randomisation.
Fixed in rpi-eeprom 28.22-1, which ships the pieeprom-2026-05-26 firmware release. Update your Raspberry Pi and reboot to apply it.
Full record: CVE-2026-13199 on NVD. Reported by Nozomi Networks Labs, fixed in rpi-eeprom#841.
Most security fixes, including boot firmware updates, reach your device through Raspberry Pi OS package updates. See our documentation on updating software for details.
Thanks to the following security researchers for reporting and helping resolve security vulnerabilities: