Executive brief
A vulnerability exists in the ESP32-audioI2S library, which is used by ESP32 microcontrollers to handle audio playback and text-to-speech functions. An attacker can send a specially crafted, oversized text request to the device, causing it to crash or potentially allowing the attacker to take control of the device. This could lead to a permanent disruption of audio services or unauthorized access to the device's operations.
Technical details
A heap-based buffer overflow exists in the `Audio::openai_speech` and `connecttospeech()` functions within `src/Audio.cpp`. The vulnerability stems from the manual construction of JSON request bodies and HTTP headers by concatenating externally controllable strings without enforcing length restrictions or boundary validation. Specifically, the library performs URL encoding on user-supplied speech text—which expands the string length—and appends the result to a fixed-size `ps_ptr` heap buffer. An unauthenticated remote attacker can provide an oversized speech string to trigger an out-of-bounds write, leading to memory corruption, denial of service (watchdog reboot), or potential arbitrary code execution. As of the advisory date, a vendor patch is reportedly under development.
Affected products
- schreibfaul1 ESP32-audioI2S 3.4.5
Timeline
- 2026-07-28: disclosed: CVE published to NVD