Remote Code Execution Vulnerability in RIOT Open-Source Operating System
CVE-2026-107838

7.5HIGH

Key Information:

Vendor

Riot-os

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107838?

A vulnerability exists within the RIOT operating system, specifically affecting the nanocoap_fileserver functionality in versions 2023.07 to 2026.07. This issue arises from the incorrect handling of response initialization during the processing of CoAP requests with excessively large tokens. When a remote client triggers this vulnerability, it can lead to the service or device task being terminated due to stale response conditions and assertion failures. As of the latest review, no patch has been released to mitigate this issue, which poses a significant risk to embedded systems that rely on RIOT OS.

Affected Version(s)

RIOT >= 2023.07, <= 2026.07

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.