PT-2026-65509 · Undefined · Undefined

CVE-2026-51268

·

Published

2026-07-28

·

Updated

2026-07-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle host() function parses untrusted host and URL input, and subsequent code uses clone from() to copy parsed host, request host, extension and query string segments into fixed heap buffers without boundary checking.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-51268

Affected Products

Undefined