Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2185929
AlmaLinux
5881
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17159
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1020158
CleanStart
3450
CRAN
14
crates.io
2720
Debian
67393
Echo
6546
GHC
3
GIT
106530
GitHub Actions
55
Go
9158
Hackage
32
Hex
353
Julia
1713
Linux
29368
Mageia
6203
Maven
6999
MinimOS
142968
npm
228525
NuGet
1860
opam
29
openEuler
8674
openSUSE
14332
OSS-Fuzz
4006
Packagist
7036
Pub
11
PyPI
25079
Red Hat
23183
Rocky Linux
4240
Root
19487
RubyGems
4709
SUSE
23047
SwiftURL
59
TuxCare
9268
Ubuntu
64512
VSCode
21
Wolfi
287393
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rrxg-g2pf-6hh4
PyPI/esphome-device-builder
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
14 Sep
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3834
PyPI/esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
10 Sep
Fix available
Severity - 8.8 (High)
GHSA-vv4j-m4vr-f3g6
PyPI/esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
09 Sep
Fix available
Severity - 8.8 (High)
PYSEC-2026-1326
PyPI/esphome
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
07 Jul
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-1330
PyPI/esphome
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
07 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-1327
PyPI/esphome
ESPHome vulnerable to Authentication bypass via Cross site request forgery
07 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-1329
PyPI/esphome
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
07 Jul
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-1328
PyPI/esphome
ESPHome vulnerable to remote code execution via arbitrary file write
07 Jul
Fix available
Severity - 7.2 (High)
GHSA-4h3h-63v6-88qx
PyPI/esphome
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
21 Jan
Fix available
Severity - 6.8 (Medium)
GHSA-mxh2-ccgj-8635
PyPI/esphome
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
02 Sep 2025
Fix available
Severity - 8.1 (High)
GHSA-5925-88xh-6h99
PyPI/esphome
ESPHome vulnerable to Authentication bypass via Cross site request forgery
21 Mar 2024
Fix available
Severity - 8.1 (High)
GHSA-9p43-hj5j-96h5
PyPI/esphome
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
06 Mar 2024
Fix available
Severity - 6.5 (Medium)
GHSA-8p25-3q46-8q2p
PyPI/esphome
ESPHome vulnerable to remote code execution via arbitrary file write
01 Mar 2024
Fix available
Severity - 7.2 (High)
GHSA-48mj-p7x2-5jfm
PyPI/esphome
Basic auth bypass in esphome
29 Sep 2021
Fix available
Severity - 8.7 (High)
PYSEC-2021-351
PyPI/esphome
github.com/esphome/esphome
See record for full details
28 Sep 2021
Fix available
PyPI - OSV