LiveActive security incident?Get immediate response
CVE Record

CVE-2026-51268: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic.

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent code uses clone_from() to copy parsed host, request host, extension and query_string segments into fixed heap buffers without boundary checking.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

ESP32-audioI2S 3.4.5 may mishandle overly long host or URL data, overflowing memory allocated on the heap. A remotely supplied input could corrupt an affected device’s memory without authentication or user interaction. The supplied CVSS rating indicates potentially severe confidentiality, integrity, and availability consequences.

Executive priority

Treat as an urgent investigation and remediation item for products using version 3.4.5, especially remotely reachable devices. The technical severity is critical, but fleet-wide business risk depends on actual library deployment and attacker control of URL inputs. No active exploitation is established by the supplied evidence.

Technical view

The dismantle_host() path parses untrusted host and URL input. Later clone_from() operations copy host, request-host, extension, and query-string segments into fixed-size heap buffers without bounds checking, producing a CWE-122 heap-based buffer overflow. The supplied CVSS v3.1 score is 9.8 with network reachability, low complexity, and no privileges or interaction required.

Likely exposure

Exposure is most likely where firmware incorporates ESP32-audioI2S 3.4.5 and processes attacker-controlled host or URL values. The supplied structured affected-product fields are unspecified, so asset owners must confirm library inclusion, deployed version, input reachability, and whether surrounding code constrains lengths.

Exploitation context

The source bundle does not report CISA KEV inclusion or provide evidence of active exploitation. It describes a remotely reachable, unauthenticated, low-complexity condition, but successful real-world impact may depend on firmware integration, memory layout, compiler protections, and input handling.

Researcher notes

The key evidence is an unchecked copy chain following host and URL segmentation. Review every destination associated with host, request host, extension, and query_string, including allocation assumptions and termination behavior. The bundle identifies version 3.4.5, but its structured vendor/product fields are unspecified and it names no fixed version.

Mitigation direction

  • Inventory firmware and source dependencies for ESP32-audioI2S 3.4.5.
  • Check upstream vendor guidance for a corrected release or approved patch.
  • Restrict untrusted host and URL input from reaching affected parsing logic.
  • Apply strict length validation before affected fields are parsed or copied.
  • Prioritize internet-reachable or remotely controlled devices for remediation.

Validation and detection

  • Confirm the exact ESP32-audioI2S version embedded in each firmware image.
  • Trace whether remote inputs can reach dismantle_host() and subsequent clone_from() calls.
  • Review destination buffer sizes and all upstream length checks.
  • Test corrected builds with oversized inputs in an isolated, authorized environment.
  • Verify deployed firmware matches the remediated build and retains input limits.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-122: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-51268 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-51268Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-122 · source CWE mapping

Heap-based Buffer Overflow

Heap-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.