Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23833

25
FAUCET Score

CVE-2026-23833 is an integer overflow vulnerability in ESPHome versions 2025.9.0 through 2025.12.6, specifically within the API component's protobuf decoder, affecting all ESPHome device platforms. This flaw allows unauthenticated denial-of-service attacks when API encryption is not utilized, causing devices to crash by reading invalid memory. With a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. Users are advised to upgrade to ESPHome 2025.12.7 or later, enable API encryption, and adhere to security best practices.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2025.9.0, < 2025.12.7CPE matchmatch criteria
cpe:2.3:a:esphome:esphome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

1.7LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 4th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: esphomeFixed in: 2025.12.7

Vendor Advisories (2)

pipGHSA-4h3h-63v6-88qxmedium

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

Jan 21, 2026
redhatCVE-2026-23833Low

ESPHome: ESPHome: Denial of Service via integer overflow in API protobuf decoder

Jan 19, 2026

References

esphome.io / guides/security_best_practices
Technical Description
github.com / esphome/esphome/commit/69d7b6e9210390051318bd8e6410727689de08d6
Patch
github.com / esphome/esphome/pull/13306
Issue TrackingPatch
github.com / esphome/esphome/security/advisories/GHSA-4h3h-63v6-88qx
MitigationPatchVendor Advisory