Please do not open a public GitHub issue for security problems.
Report suspected vulnerabilities privately by email to security@lvgl.io.
Please include, as far as you can:
- the affected version(s) and configuration (
lv_conf.htoggles, target), - a description of the impact,
- steps to reproduce or a proof of concept, and
- any suggested fix or mitigation.
We support coordinated disclosure: please give us a reasonable window to release a fix before any public disclosure. We will credit you in the advisory unless you prefer otherwise.
Fixes are made available for the actively supported releases. See the Policies page for the current support table.
LVGL publishes a machine-readable SBOM (SPDX 3.0.1) in the sbom/
folder and a human-readable component list in
COPYRIGHTS.md.
For our full security commitment, vulnerability handling process, and how LVGL supports users' EU Cyber Resilience Act (CRA) obligations, see the Security page in the documentation.