


Perceptive Security
SOC/SIEM Consultancy

Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on …
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 20:07:40
Source:
nvd.nist.gov
Mobile & IoT, Emerging Technologies
A buffer overflow vulnerability has been identified in Schreibfaul1 ESP32-audioI2S version 3.4.5, specifically within the MP3Decoder::decode() function of the MP3 decoder component. The vulnerability arises from missing size validation on untrusted mainDataBegin and nSlots values sourced from external input. An attacker capable of supplying a malicious MP3 stream could potentially exploit this flaw to corrupt memory. The affected software is commonly used in IoT and embedded systems projects built on the ESP32 platform. No patch version is explicitly mentioned in the advisory. The vulnerability is tracked as CVE-2026-51251 and has been assigned a high criticality rating. Proof-of-concept advisory details are available on GitHub.
Technical details
Mitigation steps:
Affected products:
Schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51251
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51251
https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/mp3_decoder/mp3_decoder.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
