IoT
CVE-2026-51272
9.8
Critical
EPSS n/aJul 31, 2026
Heap overflow in ESP32-audioI2S latinToUTF8 enabling code execution or DoS
This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.
executive summary
technical analysis
affected
schreibfaul1 ESP32-audioI2S 3.4.5ESP32 devices using this library
impact
Heap overflow via crafted Latin‑1 input to latinToUTF8 can cause OOB writes, enabling remote code execution, data disclosure, denial of service, or privilege escalation.
action required
Immediate action required
how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references