CVE-2026-71259

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's git source schema, which is passed to (git supports file:// natively).
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 13:24

Updated : 2026-08-26 17:13


NVD link : CVE-2026-71259

Mitre link : CVE-2026-71259

CVE.ORG link : CVE-2026-71259


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs