Junglewise Threat Intelligence

CVE-2026-45541: Espressif ESP-IDF NULL pointer dereference in esp_http_server

CVE-2026-45541 · Severity: high · CVSS 7.5 · Published 2026-06-10

Technologies: Espressif Systems ESP-IDF. Vendors: Espressif Systems.

Executive brief

Espressif ESP-IDF is a development framework used to build software for Internet of Things (IoT) devices. A flaw in its built-in web server component allows an attacker to crash the device remotely by sending a specially crafted network request. This can lead to a complete service outage for the affected IoT device before any security login or authentication occurs.

Technical details

A NULL-pointer dereference (CWE-476) exists in the 'esp_http_server' component of the ESP-IDF framework. The vulnerability is located within the 'httpd_ws_get_response_subprotocol' function in 'httpd_ws.c', where the result of a 'strtok_r' operation on the 'Sec-WebSocket-Protocol' request header is dereferenced without a prior NULL check. An unauthenticated remote attacker can exploit this by sending a malformed WebSocket handshake request, causing the server to crash (Denial of Service). The issue is patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.

Affected products

  • Espressif Systems ESP-IDF 5.2.6, 5.3.5, 5.4.4, 5.5.4, 6.0

Timeline

  • 2026-05-15: advisory: GitHub Security Advisory GHSA-3j8v-xgrq-5vg8 published
  • 2026-06-10: disclosed: CVE-2026-45541 published to NVD

References

Related threats