PT-2026-65509 · Undefined · Undefined
CVE-2026-51268
·
Published
2026-07-28
·
Updated
2026-07-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle host() function parses untrusted host and URL input, and subsequent code uses clone from() to copy parsed host, request host, extension and query string segments into fixed heap buffers without boundary checking.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined