CVE-2026-51263

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

31 Jul 2026, 15:16

Type Values Removed Values Added
Summary (en) schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request headers by directly concatenating externally controllable input and instructions strings without effective length restriction and boundary validation. An unauthenticated remote attacker can send oversized malicious string data to trigger a heap buffer overflow during string splicing, resulting in memory corruption. (en) Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
References
  • {'url': 'https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51263', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}
  • {'url': 'https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp', 'source': 'cve@mitre.org'}
CWE CWE-122
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown

28 Jul 2026, 19:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51263 - () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51263 -
CWE CWE-122

28 Jul 2026, 16:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 16:18

Updated : 2026-07-31 15:16


NVD link : CVE-2026-51263

Mitre link : CVE-2026-51263

CVE.ORG link : CVE-2026-51263


JSON object : View

Products Affected

No product.

CWE

No CWE.