Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-26453

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 版本中, 函数存在空指针解引用漏洞。当服务器处理包含 URI_PATH 选项且其数据指针为 NULL 的 COAP 消息时,若服务器在选项中查找匹配字符串 "separate" 的 URI_PATH 选项,它会直接对 调用 ,而未检查该指针是否为 NULL。当选项的 data 字段为 NULL 时,这将导致段错误(Segmentation Fault)。

AI Predicted 5.3 Difficulty: Moderate

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-26453

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-26453

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-26453

登录查看更多情报信息。

Proof of Concept for CVE-2026-26453 (2)

Same Patch Batch · n/a · 2026-08-27 · 28 CVEs total

CVE-2026-30051 free5gc 4.1.0 CreateUEContextProcedure DoS
CVE-2026-30070 free5gc v4.0.1 HandleGetSharedData拒绝服务漏洞
CVE-2026-30069 free5gc v4.0.1 UDMC空指针解引用致DoS
CVE-2026-30057 free5gc v4.1.0 拒绝服务漏洞
CVE-2026-30050 free5gc v4.1.0 ModifyAMFEventSubscriptionProcedure DoS
CVE-2026-30056 free5gc v4.0.1空指针引用致拒绝服务
CVE-2026-30072 free5gc v4.0.1空指针解引用致拒绝服务
CVE-2026-30060 free5gc v4.0.1 SUCI解析致DoS漏洞
CVE-2026-30046 Open5GS v2.7.6 NUDM-UECM断言拒绝服务
CVE-2026-30068 free5gc v4.0.1输入验证缺陷致DoS
CVE-2026-30058 free5gc 4.0.1 HTTPModifySubscription DoS漏洞
CVE-2026-30059 free5gc v4.0.1 NAS解码器拒绝服务漏洞
CVE-2026-30063 free5gc v4.0.1 NF发现端点DoS漏洞
CVE-2026-30067 free5gc 4.0.1 NRF DoS漏洞
CVE-2026-75357 B站桌面端1.17.9远程代码执行漏洞
CVE-2026-30045 open5gs v2.7.6 NF-INSTANCES整数溢出致DoS
CVE-2026-30073 free5gc v4.0.1 DoS漏洞
CVE-2026-30071 free5gc 4.0.1 RechargePut函数拒绝服务漏洞
CVE-2026-30062 free5gc v4.0.1 NGAP处理器拒绝服务漏洞
CVE-2026-30064 free5gc v4.0.1 buildFilter输入验证不当导致拒绝服务

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-26453

No comments yet


Leave a comment