CVEs we hold for Espressif
Records whose assigning authority named Espressif as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55687ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsingespressif esp-idf
CVE-2026-44358Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypointespressif shared-github-dangerjs
CVE-2026-42855arduino-esp32: Digest authentication URI mismatch bypass in WebServer allows cross-resource replay attackespressif arduino-esp32
CVE-2026-42854arduino-esp32: Stack buffer overflow in WebServer multipart boundary parsing leads to remote crash potential RCEespressif arduino-esp32
CVE-2026-41429Improper validation of NBNS name_len in arduino-esp32 NetBIOS leads to memory corruptionespressif arduino-esp32
CVE-2025-68657espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Pathespressif esp-usb
CVE-2025-68656Espressif ESP-IDF USB Host HID (Human Interface Device) Driver Descriptor Use-After-Free Vulnerabilityespressif esp-usb
CVE-2025-68622Espressif ESP-IDF USB Host UVC Class Driver has a stack buffer overflow in UVC descriptor printingespressif esp-usb
CVE-2025-68474ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handlingespressif esp-idf
CVE-2025-68473ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handlingespressif esp-idf
CVE-2025-66409ESF-IDF has an Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handlingespressif esp-idf
CVE-2025-64342ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerabilityespressif esp-idf
CVE-2025-53540CSRF Vulnerability in Firmware Update Endpoints Allows Remote Code Executionespressif arduino-esp32
CVE-2022-24893Espressif Bluetooth Mesh Stack Vulnerable to Out-of-bounds Write leading to memory buffer corruptionespressif esp-idf
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.