PT-2026-82513 · Ccoap · Ccoap

CVE-2026-26456

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ccoap version 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5
Description A null pointer dereference occurs in the server-side session management logic. This is caused by a race condition—a situation where the timing or order of events affects the correctness of the code—between the request dispatch thread and the session cleanup thread when they access shared session list nodes without proper synchronization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26456

Affected Products

Ccoap