Unknown · Espasyncwebserver · CVE-2026-54571
**Name of the Vulnerable Software and Affected Versions**
ESPAsyncWebServer versions prior to 3.11.1
**Description**
The multipart/form-data parser in src/WebRequest.cpp stores ` boundaryPosition` as an 8-bit value during the processing of the boundary by the ` parseMultipartPostByte()` function. A remote request containing a multipart boundary of exactly 256 bytes causes ` boundaryPosition` to wrap from 255 to zero. This prevents the boundary parsing loop from terminating, leading to excessive CPU consumption and triggering a FreeRTOS watchdog reset on ESP32 and ESP8266 devices.
**Recommendations**
Update to version 3.11.1.