VendorsEspressifarduino-esp32all versions
Vulnerabilities

Espressif Arduino-esp32

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-42854
arduino-esp32: Stack buffer overflow in WebServer multipart boundary parsing leads to remote crash potential RCE
Published 2026-05-12 · Analyzed
9.8EPSS 0.006
CVE-2026-41429
Improper validation of NBNS name_len in arduino-esp32 NetBIOS leads to memory corruption
Published 2026-04-24 · Analyzed
8.8EPSS 0.003
CVE-2026-42855
arduino-esp32: Digest authentication URI mismatch bypass in WebServer allows cross-resource replay attack
Published 2026-05-12 · Analyzed
7.5EPSS 0.004
CVE-2019-12586
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Published 2019-09-04 · Modified
6.5EPSS 0.015