


Perceptive Security
SOC/SIEM Consultancy

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-cont…
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 20:07:40
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities
A buffer overflow vulnerability has been identified in schreibfaul1's ESP32-audioI2S library version 3.4.5. The flaw exists in the MP3Decoder::UnpackSFMPEG1 function and is caused by missing input validation on attacker-controlled MP3 metadata. An attacker could exploit this vulnerability by crafting malicious MP3 metadata to trigger a buffer overflow. This affects embedded/IoT systems using the ESP32-audioI2S library for audio decoding. The vulnerability is tracked as CVE-2026-51252 and has been assigned a high criticality rating. Proof-of-concept advisory details are available on GitHub. Users of the affected library version should apply patches or mitigations as soon as they become available.
Technical details
Mitigation steps:
Affected products:
schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51252
http://schreibfaul1.com
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51252
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
