Impact
ESPAsyncWebServer contains an integer overflow in its multipart/form‑data parser. The _boundaryPosition variable is held in an 8‑bit field; when a client sends a multipart boundary exactly 256 bytes long, the counter wraps from 255 to 0. This is a classic integer overflow flaw, identified as CWE‑190. The parser loop never exits, consuming CPU until a FreeRTOS watchdog reset occurs. This loss of availability can affect any ESP32 or ESP8266 device running the library.
Affected Systems
The vulnerability is present in all versions of ESP32Async:ESPAsyncWebServer before 3.11.1. Devices using this library on ESP32, ESP8266, RP2040 or RP2350 with unattended insert of multipart requests are susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is less than 1 %, suggesting low current exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a malicious HTTP request sent to the device. An attacker who can reach the server can trigger the overflow, causing repeated watchdog resets and a denial of service.
OpenCVE Enrichment