28,679 Entries 2,229 Sources 5 Verticals Last sync 2 minutes Live
Self-hosted apps

ESPHome

Open Home Foundation
2026.5.3 frisch latest release
05.06.2026

frisch — vor < 7 Tagen erschienen · 0 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

6 CVE(s) zuletzt, höchste Schwere: hoch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 0, 'checked_at': '2026-06-08T02:00:22.826577', 'open_regressions': 0}
gh_etagW/"d4f98f342ec3dfe633839597c29abd347067e393ab4218f07491bf6304138182"
gh_checked_at2026-06-08T03:00:00.127675+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

A security flaw in ESPHome allows attackers to perform firmware updates through the web interface without entering the configured username and password. Affected versions up to 2021.9.1 with enabled web server and HTTP authentication are vulnerable.

CVE-2021-41104
05.06.2026
CVE
Self-hosted apps Medium

ESPHome Dashboard contains a Cross-Site Scripting vulnerability where authenticated users can inject malicious JavaScript code into configuration files to steal session cookies and perform unauthorized actions.

CVE-2024-27287
05.06.2026
CVE
Self-hosted apps High

ESPHome Dashboard component is vulnerable to Cross-Site Request Forgery attacks, allowing attackers to create, edit, or delete configuration files on behalf of logged-in users through malicious web pages.

CVE-2024-29019
05.06.2026
CVE
Self-hosted apps High

A security vulnerability in ESPHome allows authenticated attackers to read and write arbitrary files in the configuration directory, which can lead to execution of malicious code.

CVE-2024-27081
05.06.2026
CVE
Self-hosted apps High

ESPHome software on ESP-IDF platform has a web server authentication flaw that allows attackers to access protected functions without valid credentials, including over-the-air updates.

CVE-2025-57808
05.06.2026
CVE
Self-hosted apps Low

A programming flaw in ESPHome allows attackers to crash smart home devices when API encryption is not enabled.

CVE-2026-23833
05.06.2026
REL
Self-hosted apps Low frisch

Bug fixes for RC5 remote decoding polarity issues, ESP-IDF version restoration during build processes, Windows path handling for RP2040 template loading, and duplicate BLE Device Information Service resolution with string UUIDs.

2026.5.3
05.06.2026
REL
Self-hosted apps Medium frisch

Bug fixes and improvements including crash loop resolution for voice assistant configuration, Windows symlink handling, RTL8710B flash image fixes, SX126x frequency calibration correction, enhanced crash debugging for ESP32, and build system improvements for toolchain changes.

2026.5.2
02.06.2026
REL
Self-hosted apps Low bewährt

Maintenance release with dependency updates, ESP-IDF toolchain improvements, bug fixes for Python 3.11 compatibility, Tuya status pin null guard restoration, SX126x sleep wake fixes, Bluetooth proxy connection recovery, and various platform-specific enhancements for ESP32, ESP8266, and LibreTiny.

2026.5.1
24.05.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.5.0) that does not exist yet. ESPHome typically follows a different versioning scheme and this URL is not accessible.

2026.5.0
21.05.2026
REL
Self-hosted apps Medium bewährt

Beta release with breaking changes to sensor device classes for sen5x, sgp4x, and sen6x components removing incorrect AQI classifications from VOC and NOx sensors. Also includes dependency updates, CI improvements, audio enhancements, and Zigbee configuration restrictions.

2026.5.0b3
20.05.2026
REL
Self-hosted apps Low bewährt

Beta release updating zeroconf and aioesphomeapi dependencies, removing version field from ESP-IDF component files, and improving ESP32 toolchain version checking to respect framework source overrides.

2026.5.0b4
20.05.2026
REL
Self-hosted apps Medium bewährt

Beta release with ESP-IDF build improvements, TinyUSB configuration validation, toolchain warning fixes, and component updates. Breaking changes include stricter validation that rejects invalid TinyUSB and WiFi SSID configurations.

2026.5.0b2
18.05.2026
REL
Self-hosted apps bewährt

Beta release 2026.5.0b1 for ESPHome with various improvements and bug fixes. Specific changes not detailed in provided changelog link.

2026.5.0b1
14.05.2026
REL
Self-hosted apps Low bewährt

Maintenance release adding optional Device Builder toggle, fixing secrets handling with quoted keys, substitution references in dictionaries, WiFi connectivity in safe mode, and Nextion text sensor state updates.

2026.4.5
06.05.2026
REL
Self-hosted apps Medium bewährt

Fixes automation codegen types, rejects unsupported MCP23xxx interrupt options, improves ESP32 printf handling and memory usage, clamps LVGL meter values, and enhances API service argument handling with logging improvements.

2026.4.4
05.05.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing LVGL tabview triggers, Windows timezone validation, deep sleep duration types, WiFi connection state tracking, rotary encoder field types, ESP32 WiFi bootloop issues with missing NVS partitions, Nextion upload timeouts, ESP32 touch watchdog feeding, and RGB565 alpha render

2026.4.3
28.04.2026
REL
Self-hosted apps Low bewährt

Bug fix release addressing LVGL display issues, memory optimization for RGB565 animations, core variable placement fixes, null pointer crash prevention in LD2412 sensor, and improvements to IO expander interrupt handling. Also adds ESP32 Secure Boot V1 ECDSA signing support.

2026.4.2
23.04.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing multiple component issues including display rendering problems, core stability fixes, watchdog timer handling, configuration parsing regressions, and compilation errors across various hardware platforms and components.

2026.4.1
20.04.2026
REL
Self-hosted apps Low bewährt

Beta release with various bug fixes including package include support, PlatformIO progress bar rendering, micro wake word stability improvements, web server OTA reset protection, and addressable light transition fixes. Also adds ESP32-P4 PDM microphone support and API speed optimizations.

2026.4.0b3
15.04.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.4.0) that does not exist yet. ESPHome typically follows a different versioning scheme and this URL is not accessible.

2026.4.0
15.04.2026
REL
Self-hosted apps Medium Breaking

Beta release with breaking changes to package handling, fixes for API communication issues, Ethernet corruption on RP2040, and CAN bus compilation errors. Adds interrupt pin support for GPIO expanders and updates ESP32 platform to newer versions.

2026.4.0b2
13.04.2026
REL
Self-hosted apps bewährt

Beta release 2026.4.0b1 for ESPHome with various improvements and bug fixes. Specific changes not detailed in provided changelog link.

2026.4.0b1
09.04.2026
REL
Self-hosted apps Low bewährt

Bug fixes for Nextion display queue timing, LVGL image handling when dimensions change, and ESP32 build process when SDK configuration options are modified.

2026.3.3
07.04.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing WiFi roaming issues, UART communication problems, sensor calibration errors, BLE server data handling, thermostat runtime logic, and memory leaks. Includes new ESP8266 scanf float option and improved timezone validation messaging.

2026.3.2
01.04.2026
REL
Self-hosted apps Medium Breaking

Patch release fixing multiple component issues including ESP8266 WiFi power save mode mapping correction (breaking change), BLE client RSSI reporting, timezone handling, logger crashes, light gamma correction, and various sensor/communication fixes across HTTP requests, OpenThread, UART, and other c

2026.3.1
23.03.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.3.0) that does not exist yet. ESPHome typically follows a different versioning scheme and this URL is not accessible.

2026.3.0
19.03.2026
REL
Self-hosted apps Medium bewährt

Beta release containing multiple bug fixes including compilation errors, memory management issues, data races, and off-by-one errors in event pools across various components like API, speaker, ESP-NOW, USB, BLE, and MQTT modules.

2026.3.0b4
18.03.2026
REL
Self-hosted apps Medium bewährt

Beta release containing multiple bug fixes across various components including frame parser length handling, IR checksum corrections, sensor component fixes, voice assistant null pointer dereference prevention, temperature reading corrections, and HTTP request data race resolution.

2026.3.0b5
18.03.2026
REL
Self-hosted apps Low bewährt

Beta release with library updates, ESP32-S3 compatibility improvements, dependency bumps, and various bug fixes including UART debug, temperature sensor division by zero, touch coordinate mapping, battery update throttling, lightning sensor energy mask, and version parsing enhancements.

2026.3.0b3
17.03.2026
REL
Self-hosted apps Medium Breaking

Beta release with numerous bug fixes including buffer overflow and memory safety issues, compilation fixes for ESP32 variants, crash handler improvements, and one breaking change to light effect API. Includes dependency updates and platform-specific fixes for RP2040, ESP8266, and ESP32 devices.

2026.3.0b2
15.03.2026
REL
Self-hosted apps bewährt

Beta release 2026.3.0b1 for ESPHome with various improvements and bug fixes. Specific changes not detailed in the provided changelog link.

2026.3.0b1
11.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-03

2026.2.4
03.03.2026
REL
Self-hosted apps Medium Breaking

Removes broken ESP8266 SSL fingerprints option from MQTT component, fixes sprinkler timer overflow bugs, improves CC1101 radio state transitions, resolves Zigbee code generation ordering, reverts UART workarounds, corrects display board config, prevents entity automation deadlocks, fixes WiFi scan f

2026.2.3
02.03.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing multiple component issues including API connection failures, compilation errors, memory bugs, and sensor filter regressions. Fixes affect max7219digit, mipi_dsi, dsmr, haier, bme68x_bsec2, water_heater, pid, ld2420, rtttl, hmc5883l, and sensor components.

2026.2.2
26.02.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing compilation issues on newer ESP32 variants, BLE characteristic value overflow, socket allocation problems, E1.31 protocol support restoration, pulse counter glitch filter calculation error, and WiFi power management improvements to prevent brownouts.

2026.2.1
20.02.2026
REL
Self-hosted apps bewährt

Unable to analyze release notes as the provided URL appears to be for a future version (2026.2.0) that does not exist yet. ESPHome typically follows a different versioning scheme and this URL is not accessible.

2026.2.0
18.02.2026