VYPR

Wakaama

by Eclipse

Source repositories

CVEs (3)

  • CVE-2019-9004HigFeb 22, 2019
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of…

  • CVE-2026-58465HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.01

    Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing…

  • CVE-2021-41040HigFeb 1, 2022
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.