CVE-2026-107838
Received Received - Intake

RIOT OS CoAP Response Buffer Overflow via Extended Token

Vulnerability report for CVE-2026-107838, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
RIOT-OS RIOT >= 2023.07, <= 2026.07

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-252 The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107838 is a vulnerability in the RIOT operating system's nanocoap_fileserver module. It occurs when the _resp_init() function fails to allocate a response buffer but its callers ignore this failure. This leads to invalid state handling, causing an assertion failure in _calc_szx2() when processing payloads. The issue is triggered by sending a CoAP request with a large extended token when nanocoap_token_ext is enabled.

Detection Guidance

To detect this vulnerability, monitor for crashes or assertion failures in RIOT-based devices running nanocoap_fileserver with extended tokens enabled. Check logs for CoAP requests with large tokens (around 300 bytes) that may cause buffer overflows. Ensure _resp_init() return values are validated in your codebase.

Impact Analysis

This vulnerability can cause a denial of service by crashing the affected service or device task. A remote attacker can exploit it by sending a specially crafted CoAP request, leading to system unavailability. The impact is limited to systems using nanocoap_fileserver with extended tokens enabled.

Compliance Impact

The vulnerability causes a denial of service by crashing the affected RIOT OS service or device task, which could disrupt critical operations. This may impact compliance with standards requiring high availability, such as HIPAA for healthcare systems or GDPR for data processing continuity. However, the provided context does not explicitly link this vulnerability to specific compliance requirements.

Mitigation Strategies

Update RIOT-OS to a version that includes the fix for CVE-2026-107838, specifically checking the return value of _resp_init() in nanocoap_fileserver module. Disable nanocoap_token_ext if not required to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107838. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart