Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to improper null termination of a blockwise transfer path. blockwise_transfer_init() accepts a path whose length equals CONFIG_GOLIOTH_COAP_MAX_PATH_LEN and copies it using strncpy() without guaranteeing a trailing NUL byte, leaving ctx->path unterminated. A later strlen() on this buffer (in golioth_coap_client_get_internal()) can read past the end of the allocation, resulting in a crash/denial of service. The input is application-controlled (not network by default).
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-170"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23749.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23749.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"56502345576676756675422024377567781483",
"205479671246672318692771008585564255481",
"252508625059605475129627471649153268843",
"185808600035126455037782035841831069175"
],
"threshold": 0.9
},
"id": "CVE-2026-23749-b02f7d91",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/golioth/golioth-firmware-sdk/commit/0e788217ab4b61a7c1d9fadd1b4a40f5f538a26d",
"target": {
"file": "src/coap_blockwise.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "63305777133134424483942790192886599276",
"length": 389
},
"id": "CVE-2026-23749-bd8149f7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/golioth/golioth-firmware-sdk/commit/0e788217ab4b61a7c1d9fadd1b4a40f5f538a26d",
"target": {
"file": "src/coap_blockwise.c",
"function": "blockwise_transfer_init"
}
}
]
"2026-08-12T16:24:51Z"