CVE-2026-13491Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc of the component MQTT Goodbye Handler. Performing a manipulation of the argument session_id results in denial of service. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is now public and may be used. The patch is named e182471f8c5a22434346bd98da34d3b66c8c8b3e. It is recommended to apply a patch to fix this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-28: 3Technical Details · 2026-06-28: 306-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13491 A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protoco… https://www.cve.org/CVERecord?id=CVE-2026-13491 ----- Traducción: CVE-2026-13491 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑13491, noting it affects a specific function in 78 xiaozhi‑esp32 and provides a link to the official CVE record.

    0001036
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13491 A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protoco… https://www.cve.org/CVERecord?id=CVE-2026-13491

    Post summary

    The entry announces CVE-2026-13491 in xiaozhi‑esp32 up to 2.2.6, specifying the vulnerable function Application::GetInstance, but provides no exploit, patch, or active‑exploitation details.

    00010862
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13491 Denial of Service in Xiaozhi-ESP32 MQTT Goodbye Handler v... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13491 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet highlights CVE-2026-13491 as a denial‑of‑service flaw in Xiaozhi‑ESP32 MQTT Goodbye Handler, linking to Vulmon URLs for further information.

    00000135
    4.1K followersView on X

Explore more