Denial of Service Vulnerability in RIOT OS for IoT Devices
CVE-2026-107836

7.1HIGH

Key Information:

Vendor

Riot-os

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107836?

RIOT OS, an open-source operating system for Internet of Things (IoT) devices, has a vulnerability in its nanoCoAP client function, specifically the nanocoap_sock_get_slice(). In versions 2026.07 and earlier, this function improperly validates the server-controlled size and derived offset against the expected block number. A malicious CoAP server can manipulate this validation, leading to a denial of service condition by crashing the client. It risks exposing adjacent memory areas due to improper buffer calculations, which can compromise the stability of IoT applications without a fixed release to remediate the issue.

Affected Version(s)

RIOT <= 2026.07

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.