CVE-2025-34468 - CVE House
Back to Database
Status published High CVE-2025-34468

libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE

Vulnerability Description

libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially achieve remote code execution depending on compiler options and runtime memory protections. Exploitation requires the proxy logic to be enabled (i.e., the proxy request handling code path in an application using libcoap).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34468

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • SecMate

Affected Vendor

Affected Software

libcoap
Vulnerable Versions:
0, 30db3eaa1f0464722ebea2ca2d5084aebfbd344d

Timeline

Official Publish: December 31st, 2025
Last Modified: July 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)