Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58465

Опубликовано: 02 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion.

EPSS

Процентиль: 43%
0.00555
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
github
около 1 месяца назад

Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion.

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость обработчика CoAP Block1 компонента coap/block.c открытой реализации протокола LightWeight Machine-to-Machine (LwM2M) Eclipse Wakaama, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 43%
0.00555
Низкий

7.5 High

CVSS3

Дефекты

CWE-770