Executive brief
Espressif ESP-IDF is a development framework used to build software for Internet of Things (IoT) devices. A flaw in its built-in web server component allows an attacker to crash the device remotely by sending a specially crafted network request. This can lead to a complete service outage for the affected IoT device before any security login or authentication occurs.
Technical details
A NULL-pointer dereference (CWE-476) exists in the 'esp_http_server' component of the ESP-IDF framework. The vulnerability is located within the 'httpd_ws_get_response_subprotocol' function in 'httpd_ws.c', where the result of a 'strtok_r' operation on the 'Sec-WebSocket-Protocol' request header is dereferenced without a prior NULL check. An unauthenticated remote attacker can exploit this by sending a malformed WebSocket handshake request, causing the server to crash (Denial of Service). The issue is patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
Affected products
- Espressif Systems ESP-IDF 5.2.6, 5.3.5, 5.4.4, 5.5.4, 6.0
Timeline
- 2026-05-15: advisory: GitHub Security Advisory GHSA-3j8v-xgrq-5vg8 published
- 2026-06-10: disclosed: CVE-2026-45541 published to NVD
References
- https://github.com/espressif/esp-idf/commit/00a2f7fbbbd8fe6d04729022e1d5c9a49435bfe8
- https://github.com/espressif/esp-idf/commit/0dc4ee7537f3b12350f5966cecacd59bba840ec6
- https://github.com/espressif/esp-idf/commit/37508ab91124ef426a7396d30f79eba1162700c7
- https://github.com/espressif/esp-idf/commit/9fc0ca13b3b85b98d32b98cd9dc8ff9d82642b7b
- https://github.com/espressif/esp-idf/commit/dc46dc51359749e50617eb70d6f9ae298adc4fff
- https://github.com/espressif/esp-idf/commit/f88a47e4f37fb11ae4b0908cd5c80059d83198c6
- https://github.com/espressif/esp-idf/security/advisories/GHSA-3j8v-xgrq-5vg8