CVE-2026-58465

Source
https://cve.org/CVERecord?id=CVE-2026-58465
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58465.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-58465
Published
2026-07-02T17:55:12.038Z
Modified
2026-08-04T17:52:32.047992Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS
Details

Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58465.json"
}
References

Affected packages

Git / github.com/eclipse-wakaama/wakaama

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-wakaama/wakaama
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "snapshot/2026-05-26"
        }
    ]
}

Affected versions

Other
snapshots/2022-08-03
snapshots/2023-03-31
v1.*
v1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58465.json"
vanir_signatures
[
    {
        "source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "337096335392383423073743292748412706153",
                "11442959011888515220836921659688857948",
                "232379546947811818304968619741593555081",
                "224136790071251271716899748016645816539",
                "252872889566176505574087096851356962501"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58465-61425c92",
        "target": {
            "file": "core/utils.h"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "158528153232812557957671936996116711714",
                "272176330633608605602778382679201106604",
                "306144939249196516164395808661809270326",
                "3736915231569427197042036952812710344",
                "127334465535583168453793204543033871427",
                "154485193524848940712316427095798032104",
                "310127351164098418364392475415943007556",
                "325858155812552750063741325664534361825",
                "200965581496659461502317299520831222531",
                "228543374181642487848951554432646027311",
                "61469434015382375305014590593426048246",
                "220410333469309199781767063638064048073"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58465-7c8d15c0",
        "target": {
            "file": "core/utils.c"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "159709002318293063716442216406308442693",
            "length": 257.0
        },
        "id": "CVE-2026-58465-8ac25324",
        "target": {
            "function": "utils_stringCopy",
            "file": "core/utils.c"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "276280429345231685310590720332735684009",
                "34734848796319868788709654827539902401",
                "60777782290802548560222915144855854646",
                "300277431082132796910483252738073695656",
                "220911888910088752126811810820785855513",
                "316255190246198272369072621067148857583",
                "192284655751359088334787030121138864566"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58465-ac926eec",
        "target": {
            "file": "tests/core_utils_tests.c"
        },
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-04T17:52:32Z"