Libmodbus
Libmodbus: vulnerabilities and CVEs
Libmodbus has 10 published vulnerabilities, 1 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months1
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51539 | High (7.5) | 0.49% | — | Jul 13, 2026 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations. |
| CVE-2024-10918 | Critical (9.8) | 0.56% | — | Feb 27, 2025 | Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length. |
| CVE-2024-36845 | Medium (4.3) | 0.47% | — | May 31, 2024 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. |
| CVE-2024-36844 | High (7.5) | 0.61% | — | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. |
| CVE-2024-36843 | High (7.5) | 0.79% | — | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. |
| CVE-2024-34244 | High (7.5) | 0.52% | — | May 8, 2024 | libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can… |
| CVE-2023-26793 | Critical (9.8) | 0.73% | — | May 1, 2024 | libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. |
| CVE-2022-0367 | High (7.8) | 0.46% | — | Aug 29, 2022 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. |
| CVE-2019-14463 | Critical (9.1) | 1.9% | — | Jul 31, 2019 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301. |
| CVE-2019-14462 | Critical (9.1) | 2.0% | — | Jul 31, 2019 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302. |