PT-2026-82512 · Ccoap · Ccoap

CVE-2026-26453

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ccoap version 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5
Description A null pointer dereference occurs in the coap server handle session() function when processing COAP messages that include URI PATH options with NULL data pointers. The issue arises when the server searches for a URI PATH option matching the string "separate" and calls strncmp() on option list[i].data without verifying if the pointer is NULL, leading to a segmentation fault.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26453

Affected Products

Ccoap