PT-2026-102355 · Zoap · Zoap
CVE-2026-18416
·
Published
2026-09-28
·
Updated
2026-09-28
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ZoAP versions 1.8.0 through 1.9.x
Description
The CoAP link-format helper
match path uri() in subsys/net/lib/coap/coap link format.c contains an out-of-bounds read. The issue occurs when comparing a registered resource path against a URI in a Uri-Query href= option that is not NUL terminated. Because the inner character loop fails to test the index k against the option length len, the system may read beyond the end of the option value when a registered path segment is longer than the supplied URI and the URI is a prefix of it.This is reachable via unauthenticated
GET /.well-known/core?href=/<prefix> requests to devices serving /.well-known/core with the CONFIG COAP SERVER WELL KNOWN CORE configuration enabled and at least one resource declaring struct coap core metadata attributes. In the ZoAP library, the over-read occurs within the packet buffer. The impact is limited as the number of bytes read is constrained by the resource path segment length, resulting in undefined behavior rather than information disclosure or matching errors.Recommendations
For ZoAP versions 1.8.0 through 1.9.x, apply the fix that adds a
k >= len guard at the top of the inner loop in the match path uri() function to ensure all uri[k] dereferences remain within the option value.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoap