CVE-2026-45541 Details
Description
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request header during the WebSocket handshake, the tokenisation result is dereferenced without a NULL check, so a malformed header value can crash the server before any application-level authentication runs. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
A NULL-pointer dereference vulnerability has been identified in the WebSocket subprotocol negotiation of the esp_http_server component within the Espressif Internet of Things Development Framework (ESP-IDF). This issue is present in versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0. During the WebSocket handshake, the server parses the client-supplied Sec-WebSocket-Protocol header without checking for NULL values. A malformed header can cause the server to crash, bypassing any application-level authentication. The vulnerability arises when the application is built with WebSocket support enabled and registers WebSocket URI handlers that require subprotocol negotiation.
Users can upgrade to Espressif ESP-IDF versions 5.2.7, 5.3.6, 5.4.5, 5.5.5 or 6.0.1, where this vulnerability has been patched. If an immediate upgrade is not possible, WebSocket URI handlers can be registered without subprotocol negotiation, or mutual TLS authentication can be enabled on the HTTPS server to reject untrusted clients before the WebSocket parser is reached.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| espressif esp-idf | 5.2.6 5.3.5 5.4.4 5.5.4 6.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | New CVE Received | [email protected] |