esphome has 6 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The median CVSS is 8.1 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: esphome (5), device-builder (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- esphome 5
- device-builder 1
Worst active — by depth score
CVE-2025-57808High· 8.1ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header57CVE-2026-59178Critical· 9.8ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software54CVE-2024-29019High· 8.1ESPHome vulnerable to Authentication bypass via Cross site request forgery45CVE-2024-27081High· 7.2ESPHome vulnerable to remote code execution via arbitrary file write40CVE-2024-27287Medium· 6.5esphome vulnerable to stored Cross-site Scripting in edit configuration file API36
esphome vulnerabilities
CVEs affecting esphome, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-59178Critical· 9.8ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and…
CVE-2026-23833MediumESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
CVE-2025-57808High· 8.1PoCESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
CVE-2024-29019High· 8.1ESPHome vulnerable to Authentication bypass via Cross site request forgery
ESPHome vulnerable to Authentication bypass via Cross site request forgery
CVE-2024-27287Medium· 6.5esphome vulnerable to stored Cross-site Scripting in edit configuration file API
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
CVE-2024-27081High· 7.2ESPHome vulnerable to remote code execution via arbitrary file write
ESPHome vulnerable to remote code execution via arbitrary file write