PT-2026-102355 · Zoap · Zoap

CVE-2026-18416

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ZoAP versions 1.8.0 through 1.9.x
Description The CoAP link-format helper match path uri() in subsys/net/lib/coap/coap link format.c contains an out-of-bounds read. The issue occurs when comparing a registered resource path against a URI in a Uri-Query href= option that is not NUL terminated. Because the inner character loop fails to test the index k against the option length len, the system may read beyond the end of the option value when a registered path segment is longer than the supplied URI and the URI is a prefix of it.
This is reachable via unauthenticated GET /.well-known/core?href=/<prefix> requests to devices serving /.well-known/core with the CONFIG COAP SERVER WELL KNOWN CORE configuration enabled and at least one resource declaring struct coap core metadata attributes. In the ZoAP library, the over-read occurs within the packet buffer. The impact is limited as the number of bytes read is constrained by the resource path segment length, resulting in undefined behavior rather than information disclosure or matching errors.
Recommendations For ZoAP versions 1.8.0 through 1.9.x, apply the fix that adds a k >= len guard at the top of the inner loop in the match path uri() function to ensure all uri[k] dereferences remain within the option value.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18416
GHSA-M3MV-VVM4-H58G

Affected Products

Zoap