espressif
esp-idf
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at esp-idf, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-81508 | 24 Sep 2026 | esp-idf: = 6.1, = 6.0.1, = 5.5.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-55687 | 10 Jul 2026 | >= 6.0.0, < 6.0.2; >= 5.5.0, <= 5.5.4; >= 5.4.0, <= 5.4.4; <= 5.3.5 | 6.0.2 | Update reference ↗ |
| CVE-2026-46532 | 10 Jun 2026 | = 5.2.6; = 5.3.5; = 5.4.4; = 5.5.3; = 6.0 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-45542 | 10 Jun 2026 | = 5.2.6; = 5.3.5; = 5.4.4; = 5.5.4; = 6.0 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-45329 | 10 Jun 2026 | = 6.0; = 5.5.4 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-45328 | 10 Jun 2026 | = 5.5.4; = 6.0 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-45160 | 10 Jun 2026 | = 5.2.7; = 5.3.5; = 5.4.4; = 5.5.4; = 6.0.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-45541 | 10 Jun 2026 | = 6.0; = 5.5.4; = 5.4.4; = 5.3.5; = 5.2.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-25508 | 4 Feb 2026 | = 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-25507 | 4 Feb 2026 | = 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-25532 | 4 Feb 2026 | = 5.5.2; = 5.4.3; = 5.3.4; = 5.2.6; = 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-68474 | 26 Dec 2025 | esp-idf: >= 5.5-beta1, <= 5.5.1, >= 5.4-beta1, <= 5.4.3, >= 5.3-beta1, <= 5.3.4, >= 5.2-beta1, <= 5.2.6, <= 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-68473 | 26 Dec 2025 | esp-idf: >= 5.5-beta1, <= 5.5.1, >= 5.4-beta1, <= 5.4.3, >= 5.3-beta1, <= 5.3.4, >= 5.2-beta1, <= 5.2.6, <= 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-66409 | 2 Dec 2025 | >= 5.5-beta1, <= 5.5.1; >= 5.4-beta1, <= 5.4.3; >= 5.3-beta1, <= 5.3.4; >= 5.2-beta1, <= 5.2.6; <= 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-65092 | 21 Nov 2025 | = 5.5.1; = 5.4.3; = 5.3.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-64342 | 17 Nov 2025 | esp-idf: >= 5.5-beta1, < 5.5.2, >= 5.4-beta1, < 5.4.3, >= 5.3-beta1, < 5.3.5, >= 5.2-beta1, < 5.2.6, < 5.1.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-55297 | 21 Aug 2025 | < 5.0.9; >= 5.1-beta1, < 5.1.6; >= 5.2-beta1, < 5.3.3; >= 5.4-beta1, < 5.4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-52471 | 24 Jun 2025 | = 5.4.1; = 5.3.3; = 5.2.5; = 5.1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2024-53845 | 11 Dec 2024 | >= 5.3.0, < 5.3.2; >= 5.2.0, < 5.2.4; >= 5.1.0, < 5.1.6; < 5.0.8 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-28183 | 25 Mar 2024 | < 4.4.7; >= 5.0, <= 5.0.6; >= 5.1, <= 5.1.3; >= 5.2, < 5.2.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2022-24893 | 25 Jun 2022 | < 4.1.4; > 4.2.0, < 4.2.4; > 4.3.2, < 4.3.3; > 4.4.1, < 4.4.2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.