CVE-2026-71260
- EPSS 0.23%
- Veröffentlicht 05.08.2026 12:26:08
- Zuletzt bearbeitet 10.08.2026 12:17:28
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" f...
CVE-2026-71259
- EPSS 0.12%
- Veröffentlicht 05.08.2026 12:26:07
- Zuletzt bearbeitet 10.08.2026 12:17:28
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the externa...
CVE-2026-23833
- EPSS 0.28%
- Veröffentlicht 19.01.2026 17:58:50
- Zuletzt bearbeitet 04.03.2026 15:02:35
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2025.12.6, an integer overflow in the API component's protobuf decoder allows denial-of-service attacks when API encryption is not ...