CVE-2026-51273

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

31 Jul 2026, 15:16

Type Values Removed Values Added
Summary (en) In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The program reads untrusted long ID3 tag value from malicious audio files and uses unbounded appendf() to write formatted strings into ps_ptr heap buffer without length validation. Successful exploitation allows attackers to execute arbitrary code, leak sensitive memory data, cause device crash, or escalate privileges via a crafted malicious audio file. (en) Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CWE CWE-122
References
  • {'url': 'https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51273', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}
  • {'url': 'https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp', 'source': 'cve@mitre.org'}
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

28 Jul 2026, 19:17

Type Values Removed Values Added
References () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51273 - () https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51273 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-122

28 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 17:16

Updated : 2026-07-31 15:16


NVD link : CVE-2026-51273

Mitre link : CVE-2026-51273

CVE.ORG link : CVE-2026-51273


JSON object : View

Products Affected

No product.

CWE

No CWE.