VYPR
Vendor

Esphome

Products
2
CVEs
8
Across products
10
Status
Private

Products

2

Recent CVEs

8
  • CVE-2026-71259HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's…

  • CVE-2025-57808HigSep 2, 2025
    risk 0.46cvss 8.1epss 0.02

    ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a…

  • CVE-2024-29019HigApr 11, 2024
    risk 0.46cvss 8.1epss 0.00

    ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 2023.12.9 (command line installation) are vulnerable to Cross-Site Request Forgery (CSRF) allowing remote attackers to carry out…

  • CVE-2026-71260MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field correctly masked as…

  • CVE-2026-23833HigJan 19, 2026
    risk 0.42cvss 7.5epss 0.00

    ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2025.12.6, an integer overflow in the API component's protobuf decoder allows denial-of-service attacks when API encryption is not used. The bounds check `ptr +…

  • CVE-2021-41104HigSep 28, 2021
    risk 0.42cvss 7.5epss 0.01

    ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username &…

  • CVE-2024-27081HigFeb 26, 2024
    risk 0.40cvss 7.2epss 0.02

    ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the…

  • CVE-2024-27287MedMar 6, 2024
    risk 0.35cvss 6.5epss 0.01

    ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file API in dashboard component of ESPHome version 2023.12.9 (command line installation and Home Assistant…