Description
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly 256-byte multipart boundary wraps _boundaryPosition from 255 to zero, prevents the boundary parsing loop from terminating, consumes excessive CPU, and triggers a FreeRTOS watchdog reset on affected ESP32 or ESP8266 devices. This issue is fixed in version 3.11.1.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Integer Overflow
Action: Patch
AI Analysis

Impact

ESPAsyncWebServer contains an integer overflow in its multipart/form‑data parser. The _boundaryPosition variable is held in an 8‑bit field; when a client sends a multipart boundary exactly 256 bytes long, the counter wraps from 255 to 0. This is a classic integer overflow flaw, identified as CWE‑190. The parser loop never exits, consuming CPU until a FreeRTOS watchdog reset occurs. This loss of availability can affect any ESP32 or ESP8266 device running the library.

Affected Systems

The vulnerability is present in all versions of ESP32Async:ESPAsyncWebServer before 3.11.1. Devices using this library on ESP32, ESP8266, RP2040 or RP2350 with unattended insert of multipart requests are susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is less than 1 %, suggesting low current exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a malicious HTTP request sent to the device. An attacker who can reach the server can trigger the overflow, causing repeated watchdog resets and a denial of service.

Generated by OpenCVE AI on September 19, 2026 at 03:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ESPAsyncWebServer to version 3.11.1 or newer.
  • If an immediate upgrade is not feasible, reject multipart requests with a boundary length of 256 bytes or greater, or otherwise enforce stricter size limits on the boundary string.
  • Disable or remove multipart/form-data handling for untrusted clients until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 03:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Esp32async
Esp32async espasyncwebserver
Vendors & Products Esp32async
Esp32async espasyncwebserver

Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly 256-byte multipart boundary wraps _boundaryPosition from 255 to zero, prevents the boundary parsing loop from terminating, consumes excessive CPU, and triggers a FreeRTOS watchdog reset on affected ESP32 or ESP8266 devices. This issue is fixed in version 3.11.1.
Title ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denial of service
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Esp32async Espasyncwebserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:05:49.373Z

Reserved: 2026-06-15T19:15:27.343Z

Link: CVE-2026-54571

cve-icon Vulnrichment

Updated: 2026-09-21T21:05:41.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:50.843

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound