CVE-2018-12679

HIGH

CoAPthon3 1.0-1.0.1 - Denial of Service via Serialize.deserialize() Exception Mishandling

Title source: llm
STIX 2.1

Description

The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.g., the standard CoAP server, CoAP client, example collect CoAP server and client) when they receive crafted CoAP messages.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Tanganelli/CoAPthon3/issues/16

Scores

CVSS v3 7.5
EPSS 0.0145
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-502
Status published
Products (3)
coapthon3_project/coapthon3 1.0
coapthon3_project/coapthon3 1.0.1
pypi/CoAPthon3 0PyPI
Published Apr 02, 2019
Tracked Since Feb 18, 2026