PYSEC-2023-234
Withdrawn 2026-06-23. This finding no longer applies and is kept for reference. It is not used when checking packages.
Details
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/esptool
Introduced in:
0No fixed version published yet for esptool (pip). Pin to a known-safe version or switch to an alternative.