CVE-2026-51267

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

31 Jul 2026, 15:16

Type Values Removed Values Added
Summary (en) schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path and attacker-controlled query string into a path buffer, then invokes urlencode without validating the final string length. Remote attackers can construct an oversized malicious URL path and query string to trigger out-of-bounds heap write, resulting in arbitrary code execution, information disclosure, service crash, or privilege escalation. (en) Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
References
  • {'url': 'https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51267', 'source': 'cve@mitre.org'}
  • {'url': 'https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp', 'source': 'cve@mitre.org'}
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown
CWE CWE-122

28 Jul 2026, 19:17

Type Values Removed Values Added
CWE CWE-122
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

28 Jul 2026, 16:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 16:18

Updated : 2026-07-31 15:16


NVD link : CVE-2026-51267

Mitre link : CVE-2026-51267

CVE.ORG link : CVE-2026-51267


JSON object : View

Products Affected

No product.

CWE

No CWE.