{"api_version":"v1","generated_at":"2026-10-08T22:05:00+00:00","product":{"cve_count":21,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-espressif-esp-idf-4d04134527c3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/esp-idf","name":"esp-idf","next_cursor":null,"observations":[{"affected":"esp-idf: = 6.1, = 6.0.1, = 5.5.5","affected_versions_present":true,"cve_id":"CVE-2026-81508","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-81508","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T18:07:30.991Z","patch_url":"","primary_source":"","published":"2026-09-24T17:52:54.643Z"},{"affected":">= 6.0.0, < 6.0.2; >= 5.5.0, <= 5.5.4; >= 5.4.0, <= 5.4.4; <= 5.3.5","affected_versions_present":true,"cve_id":"CVE-2026-55687","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55687","fixed":"6.0.2","last_modified":"2026-07-10T20:58:56.932Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-v6r2-f6p2-88cj","primary_source":"","published":"2026-07-10T15:59:31.646Z"},{"affected":"= 5.2.6; = 5.3.5; = 5.4.4; = 5.5.3; = 6.0","affected_versions_present":true,"cve_id":"CVE-2026-46532","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46532","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T16:10:31.318Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-3pp8-42fh-3j3c","primary_source":"","published":"2026-06-10T00:35:30.465Z"},{"affected":"= 5.2.6; = 5.3.5; = 5.4.4; = 5.5.4; = 6.0","affected_versions_present":true,"cve_id":"CVE-2026-45542","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45542","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T15:16:16.137Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-9r76-858f-v6jh","primary_source":"","published":"2026-06-10T00:34:53.238Z"},{"affected":"= 6.0; = 5.5.4","affected_versions_present":true,"cve_id":"CVE-2026-45329","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45329","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T16:32:10.055Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-w82j-7q63-7pqm","primary_source":"","published":"2026-06-10T00:34:09.433Z"},{"affected":"= 5.5.4; = 6.0","affected_versions_present":true,"cve_id":"CVE-2026-45328","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45328","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T13:00:35.618Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-mmgp-73p4-92xp","primary_source":"","published":"2026-06-10T00:33:43.997Z"},{"affected":"= 5.2.7; = 5.3.5; = 5.4.4; = 5.5.4; = 6.0.1","affected_versions_present":true,"cve_id":"CVE-2026-45160","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45160","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T15:10:05.993Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-g764-gwc3-75m5","primary_source":"","published":"2026-06-10T00:26:34.381Z"},{"affected":"= 6.0; = 5.5.4; = 5.4.4; = 5.3.5; = 5.2.6","affected_versions_present":true,"cve_id":"CVE-2026-45541","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45541","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-10T14:40:16.880Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-3j8v-xgrq-5vg8","primary_source":"","published":"2026-06-10T00:25:59.233Z"},{"affected":"= 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6","affected_versions_present":true,"cve_id":"CVE-2026-25508","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25508","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T19:21:38.860Z","patch_url":"https://github.com/espressif/esp-idf/commit/0540c85140c2c06c0cbecc8843277ea676d5c4a9","primary_source":"","published":"2026-02-04T17:58:28.502Z"},{"affected":"= 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6","affected_versions_present":true,"cve_id":"CVE-2026-25507","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25507","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T19:24:17.464Z","patch_url":"https://github.com/espressif/esp-idf/commit/0540c85140c2c06c0cbecc8843277ea676d5c4a9","primary_source":"","published":"2026-02-04T17:58:18.605Z"},{"affected":"= 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6","affected_versions_present":true,"cve_id":"CVE-2026-25532","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25532","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T19:24:47.749Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-m2h2-683f-9mw7","primary_source":"","published":"2026-02-04T17:58:08.100Z"},{"affected":"esp-idf: >= 5.5-beta1, <= 5.5.1, >= 5.4-beta1, <= 5.4.3, >= 5.3-beta1, <= 5.3.4, >= 5.2-beta1, <= 5.2.6, <= 5.1.6","affected_versions_present":true,"cve_id":"CVE-2025-68474","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68474","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-29T16:51:36.305Z","patch_url":"https://github.com/espressif/esp-idf/commit/0b0b59f2e19cb99dfa1b28c284d1c5c1d276a132","primary_source":"","published":"2025-12-26T23:57:54.853Z"},{"affected":"esp-idf: >= 5.5-beta1, <= 5.5.1, >= 5.4-beta1, <= 5.4.3, >= 5.3-beta1, <= 5.3.4, >= 5.2-beta1, <= 5.2.6, <= 5.1.6","affected_versions_present":true,"cve_id":"CVE-2025-68473","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68473","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-29T16:51:42.074Z","patch_url":"https://github.com/espressif/esp-idf/commit/3286e45349b0b5c2b1422ef7e8d088b95eef895d","primary_source":"","published":"2025-12-26T23:54:47.709Z"},{"affected":">= 5.5-beta1, <= 5.5.1; >= 5.4-beta1, <= 5.4.3; >= 5.3-beta1, <= 5.3.4; >= 5.2-beta1, <= 5.2.6; <= 5.1.6","affected_versions_present":true,"cve_id":"CVE-2025-66409","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66409","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-02T18:46:18.126Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-qhf9-vr2h-jh96","primary_source":"","published":"2025-12-02T18:09:03.069Z"},{"affected":"= 5.5.1; = 5.4.3; = 5.3.4","affected_versions_present":true,"cve_id":"CVE-2025-65092","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-65092","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-21T21:56:26.041Z","patch_url":"","primary_source":"","published":"2025-11-21T21:33:03.656Z"},{"affected":"esp-idf: >= 5.5-beta1, < 5.5.2, >= 5.4-beta1, < 5.4.3, >= 5.3-beta1, < 5.3.5, >= 5.2-beta1, < 5.2.6, < 5.1.7","affected_versions_present":true,"cve_id":"CVE-2025-64342","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64342","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:04:07.698Z","patch_url":"","primary_source":"","published":"2025-11-17T17:21:01.773Z"},{"affected":"< 5.0.9; >= 5.1-beta1, < 5.1.6; >= 5.2-beta1, < 5.3.3; >= 5.4-beta1, < 5.4.1","affected_versions_present":true,"cve_id":"CVE-2025-55297","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-55297","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-08-22T11:32:48.470Z","patch_url":"https://github.com/espressif/esp-idf/commit/12b7a9e6d78012ab9184b7ccdb5524364bf7e345","primary_source":"","published":"2025-08-21T15:05:06.805Z"},{"affected":"= 5.4.1; = 5.3.3; = 5.2.5; = 5.1.6","affected_versions_present":true,"cve_id":"CVE-2025-52471","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52471","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-24T20:02:18.529Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-hqhh-cp47-fv5g","primary_source":"","published":"2025-06-24T19:53:06.066Z"},{"affected":">= 5.3.0, < 5.3.2; >= 5.2.0, < 5.2.4; >= 5.1.0, < 5.1.6; < 5.0.8","affected_versions_present":true,"cve_id":"CVE-2024-53845","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53845","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-12T16:35:00.685Z","patch_url":"","primary_source":"","published":"2024-12-11T22:35:48.528Z"},{"affected":"< 4.4.7; >= 5.0, <= 5.0.6; >= 5.1, <= 5.1.3; >= 5.2, < 5.2.1","affected_versions_present":true,"cve_id":"CVE-2024-28183","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28183","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T00:48:49.763Z","patch_url":"https://github.com/espressif/esp-idf/commit/3305cb4d235182067936f8e940e6db174e25b4b2","primary_source":"","published":"2024-03-25T14:31:28.466Z"},{"affected":"< 4.1.4; > 4.2.0, < 4.2.4; > 4.3.2, < 4.3.3; > 4.4.1, < 4.4.2","affected_versions_present":true,"cve_id":"CVE-2022-24893","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24893","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:09:01.131Z","patch_url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-7f7f-jj2q-28wm","primary_source":"","published":"2022-06-25T06:55:09.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"espressif"}}
