ESPHome
Firmware framework for ESP32 and other microcontrollers in home automation.
Vulnerabilities affecting this build
To upgrade
mbedtls 3.6.6 Upgrade to 3.6.7 or later14 vulnerabilities · an NVD scanner reports 1
- CVE-2026-50580 mbedtls missed by NVD scannershigh
Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake
- CVE-2026-50579 mbedtls missed by NVD scannershigh
Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context
- CVE-2026-50713 mbedtls missed by NVD scannershigh
Heap corruption with early renegotiation after corrupted record in DTLS
- CVE-2026-50584 mbedtls missed by NVD scannersmedium
ChaCha20 counter overflow can reuse keystream
- CVE-2026-50587 mbedtls missed by NVD scannersmedium
Timing side-channel in RSA PKCS#1 v1.5 decryption
- CVE-2026-50640 mbedtls missed by NVD scannerslow
Ignored TLS 1.3 resumption secret derivation error
- CVE-2026-50583 mbedtls missed by NVD scannerslow
Out-of-bounds read when parsing a zero-length ECC public key
- CVE-2026-50586 mbedtls missed by NVD scannerslow
Information disclosure in TLS 1.2 NewSessionTicket
- CVE-2026-73096 mbedtls missed by NVD scannersmedium
TLS 1.3 early data integrity failure due to buffered plaintext across key change
- CVE-2026-50585 mbedtls missed by NVD scannersmedium
Incomplete context reset in mbedtls_ssl_session_reset()
- CVE-2026-54441 mbedtls missed by NVD scannerslow
Signature algorithm restrictions not enforced on certificate chain
- CVE-2026-73064 mbedtls missed by NVD scannerslow
A random generator fault can compromise TLS data integrity
- CVE-2025-66442 mbedtls low
Compiler-induced constant-time violations
- CVE-2026-50588 mbedtls missed by NVD scannerslow
Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing
nimble 1.6.0 Upgrade to 1.10.0 or later12 vulnerabilities · an NVD scanner reports 12
- CVE-2026-45815 nimble high
Remote reachable assertion in ATT Read Multiple Variable Response handler
- CVE-2025-52435 nimble high
Invalid error handling in pause encryption procedure in NimBLE controller
- CVE-2024-51569 nimble high
Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
- CVE-2026-45813 nimble high
Incorrect data validation in BASS add/modify source operation
- CVE-2024-24746 nimble high
Denial of service in NimBLE Bluetooth stack
- CVE-2026-45811 nimble high
Buffer overflow in socket HCI transport
- CVE-2025-53477 nimble high
NULL Pointer Dereference in NimBLE host HCI layer
- CVE-2026-45816 nimble high
NULL pointer dereference vulnerability in SMP LTK request
- CVE-2026-45812 nimble medium
OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
- CVE-2024-47249 nimble medium
Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
- CVE-2026-46452 nimble medium
Mesh Proxy SAR reassembly unbounded append and unchecked failure
- CVE-2025-53470 nimble low
Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
esp-idf 5.5.5 Upgrade to 6.1.1 or later2 vulnerabilities · an NVD scanner reports 0
- CVE-2026-81508 espressif missed by NVD scannersmedium
Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing
- CVE-2020-26142 espressif missed by NVD scannersmedium
Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame
espasyncwebserver 3.9.6 Upgrade to 3.11.2 or later2 vulnerabilities · an NVD scanner reports 0
- CVE-2026-54571 espasyncwebserver missed by NVD scannershigh
Integer overflow in multipart boundary parser causes denial of service
- CVE-2026-62966 espasyncwebserver missed by NVD scannershigh
Null-pointer write in ESPAsyncWebServer multipart parser
To look at
lwip 2.2.0 A vendor fork: check whether it carries the fixes1 vulnerability · an NVD scanner reports 1
- CVE-2020-22283 silabs high
Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
openthread 2026.07.0.. A vendor fork: check whether it carries the fixes1 vulnerability · an NVD scanner reports 0
- CVE-2023-2626 openthread missed by NVD scannershigh
Missing Key ID Mode validation when processing 6LoWPAN frames
freertos-kernel version not stated Bundled in an SDK with no version of its own. Check the advisories.5 vulnerabilities · an NVD scanner reports 5
- CVE-2026-77235 freertos high
Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel
- CVE-2026-77236 freertos high
Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel
- CVE-2026-77234 freertos high
Improper input validation in FreeRTOS-Kernel timer command handling
- CVE-2024-28115 freertos high
Potential Privilege Escalation in FreeRTOS Kernel ARMv7-M MPU ports and ARMv8-M ports with MPU support enabled
- CVE-2026-77237 freertos medium
Missing type validation in xQueueAddToSet in FreeRTOS-Kernel
arduinocore-api version not stated Bundled in an SDK with no version of its own. Check the advisories.1 vulnerability · an NVD scanner reports 0
- CVE-2026-91018 lwIP missed by NVD scannershigh
lwIP (Lightweight IP)
coex-lib version not stated Bundled in an SDK with no version of its own. Check the advisories.1 vulnerability · an NVD scanner reports 0
- CVE-2021-26706 silabs missed by NVD scannersmedium
Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations
No advisory source
- adafruit-tinyusb-arduino 3.7.7
- arduino-gas-index-algorithm 3.2.1
- arduino-mlx90393 1.0.2
- arduino-pico 6.0.0
- arduinojson 7.4.3
- asyncmqttclient-esphome 2.0.0
- asynctcp 3.4.91
- asyncudp
- bearssl-esp8266
- cmock v2.5.2-2-geeecc49ce8af
- dlms-parser 1.1.0
- dm9051 1.1.0
- dsmr-parser 1.9.0
- eppp-link 1.1.5
- esp-audio-libs 3.2.1
- esp-ble-mesh-lib
- esp-dsp 1.8.2
- esp-hosted 2.12.12
- esp-hub75 0.3.5
- esp-micro-speech-features 1.2.3
- esp-phy-lib
- esp-thread-lib
- esp-wifi-remote 1.6.3
- esp-wireguard 0.4.5
- esp-zigbee-lib 2.0.4
- esp32-audioi2s 2.3.0
- esp32-bt-lib
- esp32-camera 2.1.7
- esp32-wifi-lib
- esp32c2-bt-lib
- esp32c3-bt-lib
- esp32c5-bt-lib
- esp32c6-bt-lib
- esp32h2-bt-lib
- esp8266-arduino-core 3.1.2
- esp8266-nonos-sdk 2.2.0
- esp8266sdfat
- esp82xx-nonos-linklayer
- espasynctcp 2.0.0
- esphost
- espsoftwareserial 8.0.1
- ethernet
- fastled 3.10.3..3.10.4
- haierprotocol 0.9.31
- heatpumpir 1.0.42
- http-parser
- improv 1.2.7
- ip101 1.0.0
- joystick
- keyboard
- ksz80xx 1.0.0
- lan867x 2.0.0
- lan87xx 1.0.0
- littlefs 2.11.1
- lvgl 9.5.0
- mcux-sdk-middleware-usb 1.4.1
- mdns 1.12.0
- micro-flac 0.2.0
- micro-opus 0.4.1
- micro-wav 0.2.0
- mideauart 1.1.9..
- midiusb
- mouse
- mqtt 1.0.0
- neopixelbus 2.8.0
- noise-c 0.1.30
- pico-sdk 2.3.0
- pngle 1.1.0
- pyserial 3.5
- qr-code-generator-library 1.7.0
- rpasynctcp 1.3.2
- rtl8201 1.0.1
- sdfat 2.3.1
- spiffs 0.2-265-gad902ca
- spiftl
- stm32-dp83848 1.0.0
- tflite-micro 1.3.3~1
- tinygpsplus v1.1.0
- tinyusb 2.2.1
- tlsf
- tm1651 1.0.1
- unity v2.6.0-RC1
- updater
- uzlib
- w5500 1.0.1
- wifi-remote-over-eppp 0.3.3
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.