esphome@2025.8.0b3 vulnerabilities

ESPHome is a system to configure your microcontrollers by simple yet powerful configuration files and control them remotely through Home Automation systems.

  • latest version

    2025.9.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    37 minutes ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the esphome package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Incorrect Implementation of Authentication Algorithm

    esphome is a Make creating custom firmwares for ESP32/ESP8266 super easy.

    Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm in the web_server authentication process. An attacker can gain unauthorized access to web server functionality, including over-the-air updates if enabled, by supplying an empty or incomplete base64-encoded Authorization header.

    How to fix Incorrect Implementation of Authentication Algorithm?

    Upgrade esphome to version 2025.8.1 or higher.

    [,2025.8.1)