{"id":"CVE-2026-27703","summary":"RIOT has an Out-of-Bounds Write in nanoCoAP Handler","details":"RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier, the default handler for the well_known_core resource coap_well_known_core_default_handler writes user-provided option data and other data into a fixed size buffer without validating the buffer is large enough to contain the response. This vulnerability allows an attacker to corrupt neighboring stack location, including security-sensitive addresses like the return address, leading to denial of service or arbitrary code execution.","aliases":["GHSA-qgj4-9jff-93cj"],"modified":"2026-08-12T03:51:36.884818566Z","published":"2026-03-11T19:38:02.866Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27703.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27703.json"},{"type":"ADVISORY","url":"https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-qgj4-9jff-93cj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27703"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/riot-os/riot","events":[{"introduced":"0"},{"last_affected":"c699e2e20a6c2d0fd45daa766d7a192cb33e579f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2026.01"}],"source":"AFFECTED_FIELD"}}],"versions":["2026.01-devel","2025.10-RC1","2025.10-devel","2025.07-RC1","2025.07-devel","2025.04-RC1","2025.04-devel","2025.01-RC1","2025.01-devel","2024.10-RC1","2024.10-devel","2024.07-RC1","2024.04","2024.07-devel","2024.04-RC1","2024.04-devel","2024.01-RC1","2024.01-devel","2023.10-RC1","2023.10-devel","2023.07-RC1","2023.07-devel","2023.04-RC1","2023.04-devel","2023.01-RC1","2023.01-devel","2022.10-RC1","2022.10-devel","2022.07-RC1","2022.07-devel","2022.04-RC1","2022.04-devel","2022.01-RC1","2022.01-devel","2021.10-RC1","2021.10-devel","2021.07-RC1","2021.07-devel","2021.04-RC1","2021.04-devel","2021.01-RC1","2021.01-devel","2020.10-RC1","2020.10-devel","2020.07-RC1","2020.07-devel","2020.04-RC1","2020.04-devel","2020.01-RC1","2020.01-devel","2019.10-RC1","2019.10-devel","2019.07-RC1","2019.07-devel","2019.04-RC1","2019.04-devel","2019.01-RC1","2018.10-devel","2018.07-RC1","2019.01-devel","2018.10-RC1","2018.07-devel","2018.04-RC1","2018.04-devel","2018.01-RC1","2018.01-devel","2017.10-RC1","2017.10-devel","2017.07-RC1","2017.07-devel","2017.04-RC1","2017.04-devel","2017.01-RC1","2017.01-devel","2016.10-RC1","2016.10-devel","2016.07-RC2","2016.07-RC1","2016.04-RC1","2016.07-devel","2016.03-devel","2015.12-RC1","2015.12-devel","2015.09-RC1","2014.12","2014.05","2014.01","2013.08"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27703.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}