CVE-2026-71259: Esphome
High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's git source schema, which is passed to (git supports file:// natively).
Affected products
- Esphome Esphome: up to and including 2026.7.0
Published 2026-08-05. Last modified 2026-08-26.