CVE-2026-51271
A critical heap-based buffer overflow exists in the WAV header parser of schreibfaul1 ESP32-audioI2S 3.4.5. Malicious WAV files can trigger out‑of‑bounds reads and writes, allowing attackers to execute arbitrary code or crash the device. The flaw is caused by oversized chunk sizes or skip values in the file header.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
schreibfaul1 ESP32-audioI2S version 3.4.5, used in ESP32 audio projects that parse WAV files.
Real-world impact
An attacker who can supply a crafted WAV file to the affected firmware could run arbitrary code on the device, steal data, or cause a denial of service.
Why this severity
The CVSS score of 9.6 reflects network‑based exploitation (AV:N), low attack complexity (AC:L), no privileges required (PR:N), user interaction needed (UI:R), and a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H).
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources