Libcoap is a lightweight constrained application protocol (CoAP) library embedded across IoT, embedded systems, and low-resource networking applications, giving it prominence in the landscape despite a focused product scope. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and the exposure recurs through memory-safety weakness classes including NULL-pointer dereferences, out-of-bounds reads and writes, buffer overflows, and improper array indexing that are endemic to C implementations handling untrusted network input. Defenders should prioritize tracking downstream products and devices that bundle this library and inventory affected deployments in constrained and internet-connected environments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libcoap over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34468CRITICAL libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied in | Dec 31, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-29013CRITICAL libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bound | Apr 17, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-65493HIGH NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_da | Nov 24, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-65495HIGH Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate th | Nov 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-65494HIGH NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certifica | Nov 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-59391MEDIUM A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain conf | Dec 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-0962HIGH A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the componen | Jan 27, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-31031HIGH An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow. | Apr 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-30362HIGH Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed | Jun 23, 2023 | 7.5 | 20 | NO | NO |
CVE-2025-65501MEDIUM Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() retur | Nov 24, 2025 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libcoap.
Media articles that mention a CVE ID that affects a product developed by Libcoap — matched by CVE ID, not by vendor name.