PT-2026-95066 · Unknown · Espasyncwebserver

·

CVE-2026-54571

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ESPAsyncWebServer versions prior to 3.11.1
Description The multipart/form-data parser in src/WebRequest.cpp stores boundaryPosition as an 8-bit value during the processing of the boundary by the parseMultipartPostByte() function. A remote request containing a multipart boundary of exactly 256 bytes causes boundaryPosition to wrap from 255 to zero. This prevents the boundary parsing loop from terminating, leading to excessive CPU consumption and triggering a FreeRTOS watchdog reset on ESP32 and ESP8266 devices.
Recommendations Update to version 3.11.1.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54571
GHSA-4PHX-FCJ6-46R4

Affected Products

Espasyncwebserver