CVE-2026-23833 | ESPHome up to 2025.12.6 API components/api/proto.cpp field_length integer overflow (GHSA-4h3h-63v6-88qx)
A vulnerability was found in ESPHome up to 2025.12.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file components/api/proto.cpp of the component API Component. The manipulation of the argument field_length results in integer overflow.
This vulnerability is cataloged as CVE-2026-23833. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.