Esp-idf
This hub aggregates every CVE we track for Esp-idf, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
3
Critical
13
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH13CRITICAL3
Monthly trend
0
0
0
1
1
0
0
0
1
0
0
1
0
1
0
0
0
3
0
3
0
0
0
6
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Esp-idf.
- CVE-2026-46532ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser4.6
- CVE-2026-45542ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth7.1
- CVE-2026-45329ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers7.1
- CVE-2026-45328ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers9.3
- CVE-2026-45160ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser6.5
- CVE-2026-45541ESF-IDF: Remote Null Pointer Dereference in WebSocket Server7.5
- CVE-2026-25508ESF-IDF Has Memory Safety Vulnerabilities in BLE Provisioning6.3
- CVE-2026-25507ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning6.3
- CVE-2026-25532ESF-IDF is Vulnerable to WPS Enrollee Fragment Integer Underflow6.3
- CVE-2025-68474ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling7.6
- CVE-2025-68473ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling8.6
- CVE-2025-66409ESF-IDF has an Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling9.1
- CVE-2025-55297ESF-IDF BluFi Example Memory Overflow Vulnerability8.8
- CVE-2025-52471ESP-NOW Integer Underflow Vulnerability Advisory9.8
- CVE-2024-53406Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, c...8.8
Product normalization is registry-driven with AI assist and human review. How it works