An issue in coap_pdu.c in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
coap_pdu.c
{ "urgency": "not yet assigned" }