CVE-2026-55687: Espressif Esp-Idf
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg_parse_marker.c because the attacker-controlled DQT marker Tq nibble is used as an index into the qt_tbl array without validating that it is in the range 0..3, allowing malformed JPEG input to corrupt stack memory and reliably trigger a denial of service. This issue is fixed in version 6.0.2 and is expected to be fixed in versions 5.5.5, 5.4.5, and 5.3.6.
Affected products
- Espressif Esp-Idf: from 6.0.0, before 6.0.2 (fixed in 6.0.2); from 5.5.0, up to and including 5.5.4; from 5.4.0, up to and including 5.4.4; up to and including 5.3.5
Published 2026-07-10. Last modified 2026-07-10.