Skip to main content

CVE-2026-18416: bounds in zephyrproject zephyr

0
Low
VulnerabilityCVE-2026-18416cvecve-2026-18416
Published: 09/28/2026 (09/28/2026, 20:00:02 UTC)
Source: CVE Database V5
Vendor/Project: zephyrproject
Product: zephyr

Description

CVE-2026-18416 is a low-severity vulnerability in the Zephyr project affecting the CoAP server subsystem. It involves a bounds over-read in the match_path_uri() function when processing URI query options in unauthenticated GET requests to /.well-known/core. The flaw causes reading past the end of a URI option value buffer, leading to undefined behavior but no information disclosure or incorrect matching. The issue is fixed by adding a boundary check in the code.

CVSS v3.1

Score 3.7low

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected software

zephyrproject

zephyr

Affected versions
>=1.8.0 <4.4.2
GitHub Actionsmore threats →cve
zephyr
pkg:github/zephyr
Affected versions
>=1.8.0 <4.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 20:47:58 UTC

Technical Analysis

The vulnerability exists in the CoAP link-format helper match_path_uri() function in Zephyr's subsys/net/lib/coap/coap_link_format.c. The function compares a registered resource path against a URI from a Uri-Query href= option that is not NUL terminated. The inner loop advances an index without checking against the option length, causing an over-read past the end of the URI buffer when the registered path segment is longer than the URI and the URI is a prefix. This over-read reads uninitialized stack memory but does not reach the receive buffer or influence response matching. The impact is limited to undefined behavior. The fix adds a boundary check to prevent reading beyond the option length.

Potential Impact

The vulnerability results in a bounded out-of-bounds read of uninitialized stack memory, which leads to undefined behavior. It does not cause information disclosure, incorrect resource matching, or denial of service. The over-read is limited to approximately one byte and cannot influence the CoAP server response.

Mitigation Recommendations

A fix is available that adds a boundary check to prevent out-of-bounds reads in match_path_uri(). Users should upgrade to Zephyr version 4.4.2 or later where this issue is resolved. No additional mitigation is required as the vulnerability does not lead to information disclosure or denial of service.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
zephyr
Date Reserved
2026-07-30T17:54:12.762Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abacf16f7a7c541062b9a5b

Added to database: 09/28/2026, 20:33:26 UTC

Last enriched: 09/28/2026, 20:47:58 UTC

Last updated: 09/28/2026, 20:47:58 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses