PT-2026-48352 · Espressif Systems · Esp-Idf
CVE-2026-45541
·
Published
2026-06-10
·
Updated
2026-06-11
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ESF-IDF version 5.2.6
ESF-IDF version 5.3.5
ESF-IDF version 5.4.4
ESF-IDF version 5.5.4
ESF-IDF version 6.0
Description
A NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the
esp http server component. During the WebSocket handshake, the server parses the client-supplied Sec-WebSocket-Protocol request header, but the tokenisation result is dereferenced without a NULL check. Consequently, a malformed header value can cause the server to crash before any application-level authentication is executed.Recommendations
Update version 5.2.6 to 5.2.7
Update version 5.3.5 to 5.3.6
Update version 5.4.4 to 5.4.5
Update version 5.5.4 to 5.5.5
Update version 6.0 to 6.0.1
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esp-Idf