Skip to content
IoT

CVE-2026-51263

9.8
Critical
EPSS n/aJul 29, 2026

Heap buffer overflow in ESP32-audioI2S openai_speech allowing remote memory corruption.

This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.

executive summary
technical analysis
affected
schreibfaul1 ESP32-audioI2S 3.4.5ESP32-based devices using Audio::openai_speech
impact

Unauthenticated remote heap overflow via oversized strings can cause memory corruption, device crashes, or remote code execution on ESP32 devices.

action required

Immediate action required

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free