CVE-2026-51254 | schreibfaul1 ESP32-audioI2S 3.4.5 MP3 Decoder mp3_decoder.cpp MP3Decoder::GetBits nBits integer underflow

SecurityVulns

A vulnerability categorized as critical has been discovered in schreibfaul1 ESP32-audioI2S 3.4.5. Affected is the function MP3Decoder::GetBits of the file src/mp3_decoder/mp3_decoder.cpp of the component MP3 Decoder. Such manipulation of the argument nBits leads to integer underflow.

This vulnerability is listed as CVE-2026-51254. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More