top of page
perceptive_background_267k.jpg

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically spli…

Published:

27 July 2026 at 22:00:00

Alert date:

28 July 2026 at 20:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities

A heap-based buffer overflow vulnerability (CVE-2026-51266) has been identified in schreibfaul1 ESP32-audioI2S version 3.4.5. The flaw exists in the HTTP request header construction logic, where attacker-controlled inputs such as host name, path, query string, and HTTP header fields are dynamically spliced into a fixed-size heap buffer (ps_ptr) without proper size validation or boundary checks. Remote attackers can exploit this vulnerability by crafting oversized network request parameters to trigger an out-of-bounds heap write. Successful exploitation can lead to arbitrary code execution on the affected device. The vulnerability affects IoT/embedded systems using the ESP32 platform running this audio library. No authentication appears to be required for exploitation, making this a significant remote attack surface. A proof-of-concept advisory has been published on GitHub alongside references to the vulnerable source file.

Technical details

Mitigation steps:

Affected products:

schreibfaul1 ESP32-audioI2S 3.4.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page