Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libcoap

First CVE: Jun 19, 2023Active for: 3 yearsTotal CVEs: 16
33.4
VTI Score
Medium

Libcoap is a lightweight constrained application protocol (CoAP) library embedded across IoT, embedded systems, and low-resource networking applications, giving it prominence in the landscape despite a focused product scope. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and the exposure recurs through memory-safety weakness classes including NULL-pointer dereferences, out-of-bounds reads and writes, buffer overflows, and improper array indexing that are endemic to C implementations handling untrusted network input. Defenders should prioritize tracking downstream products and devices that bundle this library and inventory affected deployments in constrained and internet-connected environments; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libcoap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2023
3 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-34468CRITICAL
libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied in
Dec 31, 20259.832NONO
CVE-2026-29013CRITICAL
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bound
Apr 17, 20269.829NONO
CVE-2025-65493HIGH
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_da
Nov 24, 20257.526NONO
CVE-2025-65495HIGH
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate th
Nov 24, 20257.525NONO
CVE-2025-65494HIGH
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certifica
Nov 24, 20257.525NONO
CVE-2025-59391MEDIUM
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain conf
Dec 8, 20256.522NONO
CVE-2024-0962HIGH
A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the componen
Jan 27, 20247.822NONO
CVE-2024-31031HIGH
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Apr 17, 20247.521NONO
CVE-2023-30362HIGH
Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed
Jun 23, 20237.520NONO
CVE-2025-65501MEDIUM
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() retur
Nov 24, 20254.319NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
50%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (56.3%)
Unknown0 (0.0%)
Required7 (43.8%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None15 (93.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libcoap.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libcoap — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libcoap's Products

View all 3 CNAs →

Top CWEs