esphome vulnerabilities
CVEs whose affected-version data names the esphome package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-23833MediumESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
▾ Sunlitesphome · esphomeEPSS 0.30%via OSV
CVE-2025-57808High· 8.1PoCESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
▾ Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2024-29019High· 8.1ESPHome vulnerable to Authentication bypass via Cross site request forgery
ESPHome vulnerable to Authentication bypass via Cross site request forgery
▾ Twilightesphome · esphomeEPSS 0.27%via OSV
CVE-2024-27287Medium· 6.5esphome vulnerable to stored Cross-site Scripting in edit configuration file API
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
▾ Sunlitesphome · esphomeEPSS 0.68%via OSV
CVE-2024-27081High· 7.2ESPHome vulnerable to remote code execution via arbitrary file write
ESPHome vulnerable to remote code execution via arbitrary file write
▾ Twilightesphome · esphomeEPSS 1.5%via OSV