HIGH

CVE-2026-71259

2026-08-05 CVSS v3.1
CVSS
8.6

Description

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's git source schema, which is passed to (git supports file:// natively).

Weakness (CWE)

CWE-184

EPSS Score

0.12%
Probability of exploitation in next 30 days
2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE