CVE-2026-51254

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

31 Jul 2026, 15:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51254', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}
  • {'url': 'https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/mp3_decoder/mp3_decoder.cpp', 'source': 'cve@mitre.org'}
Summary (en) schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked bit reading operations. The lack of validation on the nBits parameter causes the cachedBits counter to underflow to negative values, leading to invalid bit manipulation, incorrect bitstream parsing, application crash, or arbitrary code execution via a specially crafted MP3 file. (en) Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CWE CWE-191
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

28 Jul 2026, 19:17

Type Values Removed Values Added
References () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51254 - () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51254 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-191

28 Jul 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 15:17

Updated : 2026-07-31 15:16


NVD link : CVE-2026-51254

Mitre link : CVE-2026-51254

CVE.ORG link : CVE-2026-51254


JSON object : View

Products Affected

No product.

CWE

No CWE.