CVE-2026-18416: bounds in zephyrproject zephyr
CVE-2026-18416 is a low-severity vulnerability in the Zephyr project affecting the CoAP server subsystem. It involves a bounds over-read in the match_path_uri() function when processing URI query options in unauthenticated GET requests to /.well-known/core. The flaw causes reading past the end of a URI option value buffer, leading to undefined behavior but no information disclosure or incorrect matching. The issue is fixed by adding a boundary check in the code.
AI Analysis
Technical Summary
The vulnerability exists in the CoAP link-format helper match_path_uri() function in Zephyr's subsys/net/lib/coap/coap_link_format.c. The function compares a registered resource path against a URI from a Uri-Query href= option that is not NUL terminated. The inner loop advances an index without checking against the option length, causing an over-read past the end of the URI buffer when the registered path segment is longer than the URI and the URI is a prefix. This over-read reads uninitialized stack memory but does not reach the receive buffer or influence response matching. The impact is limited to undefined behavior. The fix adds a boundary check to prevent reading beyond the option length.
Potential Impact
The vulnerability results in a bounded out-of-bounds read of uninitialized stack memory, which leads to undefined behavior. It does not cause information disclosure, incorrect resource matching, or denial of service. The over-read is limited to approximately one byte and cannot influence the CoAP server response.
Mitigation Recommendations
A fix is available that adds a boundary check to prevent out-of-bounds reads in match_path_uri(). Users should upgrade to Zephyr version 4.4.2 or later where this issue is resolved. No additional mitigation is required as the vulnerability does not lead to information disclosure or denial of service.
CVE-2026-18416: bounds in zephyrproject zephyr
Description
CVE-2026-18416 is a low-severity vulnerability in the Zephyr project affecting the CoAP server subsystem. It involves a bounds over-read in the match_path_uri() function when processing URI query options in unauthenticated GET requests to /.well-known/core. The flaw causes reading past the end of a URI option value buffer, leading to undefined behavior but no information disclosure or incorrect matching. The issue is fixed by adding a boundary check in the code.
CVSS v3.1
Score 3.7low
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the CoAP link-format helper match_path_uri() function in Zephyr's subsys/net/lib/coap/coap_link_format.c. The function compares a registered resource path against a URI from a Uri-Query href= option that is not NUL terminated. The inner loop advances an index without checking against the option length, causing an over-read past the end of the URI buffer when the registered path segment is longer than the URI and the URI is a prefix. This over-read reads uninitialized stack memory but does not reach the receive buffer or influence response matching. The impact is limited to undefined behavior. The fix adds a boundary check to prevent reading beyond the option length.
Potential Impact
The vulnerability results in a bounded out-of-bounds read of uninitialized stack memory, which leads to undefined behavior. It does not cause information disclosure, incorrect resource matching, or denial of service. The over-read is limited to approximately one byte and cannot influence the CoAP server response.
Mitigation Recommendations
A fix is available that adds a boundary check to prevent out-of-bounds reads in match_path_uri(). Users should upgrade to Zephyr version 4.4.2 or later where this issue is resolved. No additional mitigation is required as the vulnerability does not lead to information disclosure or denial of service.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-07-30T17:54:12.762Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abacf16f7a7c541062b9a5b
Added to database: 09/28/2026, 20:33:26 UTC
Last enriched: 09/28/2026, 20:47:58 UTC
Last updated: 09/28/2026, 20:47:58 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.