CVE-2026-71259: Esphome

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's git source schema, which is passed to (git supports file:// natively).

Affected products

  • Esphome Esphome: up to and including 2026.7.0

Published 2026-08-05. Last modified 2026-08-26.