PT-2026-65533 · Unknown · Esp32-Audioi2S

CVE-2026-51274

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESP32-audioI2S version 3.4.5
Description A heap-based buffer overflow exists in the ID3v2 SYLT synchronized lyrics parser within the audiolib. This occurs because of missing bounds validation on the frame size and improper memory access during the parsing of lyrics. A remote attacker can exploit this by providing a crafted MP3 file, potentially leading to a denial of service (application crash), information disclosure, or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51274

Affected Products

Esp32-Audioi2S