Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion.
{
"cwe_ids": [
"CWE-770"
],
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58465.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58465.json"
[
{
"source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"337096335392383423073743292748412706153",
"11442959011888515220836921659688857948",
"232379546947811818304968619741593555081",
"224136790071251271716899748016645816539",
"252872889566176505574087096851356962501"
],
"threshold": 0.9
},
"id": "CVE-2026-58465-61425c92",
"target": {
"file": "core/utils.h"
},
"deprecated": false
},
{
"source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"158528153232812557957671936996116711714",
"272176330633608605602778382679201106604",
"306144939249196516164395808661809270326",
"3736915231569427197042036952812710344",
"127334465535583168453793204543033871427",
"154485193524848940712316427095798032104",
"310127351164098418364392475415943007556",
"325858155812552750063741325664534361825",
"200965581496659461502317299520831222531",
"228543374181642487848951554432646027311",
"61469434015382375305014590593426048246",
"220410333469309199781767063638064048073"
],
"threshold": 0.9
},
"id": "CVE-2026-58465-7c8d15c0",
"target": {
"file": "core/utils.c"
},
"deprecated": false
},
{
"source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "159709002318293063716442216406308442693",
"length": 257.0
},
"id": "CVE-2026-58465-8ac25324",
"target": {
"function": "utils_stringCopy",
"file": "core/utils.c"
},
"deprecated": false
},
{
"source": "https://github.com/eclipse-wakaama/wakaama/commit/94ff56f77a2d24a5890e0e703809a47633aa7d4b",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"276280429345231685310590720332735684009",
"34734848796319868788709654827539902401",
"60777782290802548560222915144855854646",
"300277431082132796910483252738073695656",
"220911888910088752126811810820785855513",
"316255190246198272369072621067148857583",
"192284655751359088334787030121138864566"
],
"threshold": 0.9
},
"id": "CVE-2026-58465-ac926eec",
"target": {
"file": "tests/core_utils_tests.c"
},
"deprecated": false
}
]
"2026-08-04T17:52:32Z"