VendorsLibcoaplibcoapall versions
Vulnerabilities

Libcoap libcop

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-34468
libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE
Published 2025-12-31 · Analyzed
9.8EPSS 0.007
CVE-2026-29013
libcoap Out-of-Bounds Read in OSCORE CBOR Unwrap Handling
Published 2026-04-17 · Analyzed
9.8EPSS 0.005
CVE-2024-0962
obgm libcoap Configuration File coap_oscore.c get_split_entry stack-based overflow
Published 2024-01-27 · Modified
7.8EPSS 0.008
CVE-2024-31031
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Published 2024-04-17 · Modified
7.5EPSS 0.009
CVE-2023-30362
Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.
Published 2023-06-23 · Modified
7.5EPSS 0.008
CVE-2025-65493
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL.
Published 2025-11-24 · Analyzed
7.5EPSS 0.004
CVE-2025-65494
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.
Published 2025-11-24 · Analyzed
7.5EPSS 0.002
CVE-2025-65495
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter.
Published 2025-11-24 · Analyzed
7.5EPSS 0.002
CVE-2023-35862
libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.
Published 2023-06-19 · Modified
6.5EPSS 0.008
CVE-2025-59391
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.
Published 2025-12-08 · Analyzed
6.5EPSS 0.003
CVE-2025-65496
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2025-65497
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2025-65498
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2025-65499
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2025-65500
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2025-65501
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003