Executive brief
A vulnerability exists in the software core used by ESP32 microcontrollers to handle web traffic. By sending a specially crafted web request, an attacker can cause the device to crash or potentially take control of its operations. This affects any device using the Arduino WebServer library for tasks like file uploads, potentially leading to service outages or unauthorized access to the device's functions.
Technical details
A stack-based buffer overflow (CWE-121) exists in the WebServer multipart form parser of the arduino-esp32 core. The vulnerability occurs in `Parsing.cpp` because the code allocates a Variable Length Array (VLA) on the stack using a size derived from the 'boundary' parameter of the 'Content-Type' HTTP header without length validation. Since the ESP32 `loopTask` typically has an 8192-byte stack, an attacker sending a boundary string exceeding ~8000 characters can overflow the stack into heap memory. This can be triggered by an unauthenticated remote attacker via a single POST request to any endpoint using the multipart parser (e.g., file upload handlers). The issue is resolved in version 3.3.8 by enforcing the RFC 2046 limit of 70 characters for boundary strings.
Affected products
- Espressif Systems arduino-esp32 <= 3.3.7
Timeline
- 2026-03-27: disclosed: Vulnerability reported to Espressif
- 2026-04-01: patched: Fix merged in PR #12486
- 2026-04-12: advisory: Fix released in version 3.3.8
- 2026-05-12: other: CVE published to NVD