Wakaama Eclipse Wakaama

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Eclipse Wakaama.

By the Year

In 2026 there have been 1 vulnerability in Eclipse Wakaama with an average score of 7.5 out of ten. Wakaama did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 7.50
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 7.50
2021 0 0.00
2020 0 0.00
2019 1 0.00

It may take a day or so for new Wakaama vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Eclipse Wakaama Security Vulnerabilities

Eclipse Wakaama Unbounded Memory Allocation in CoAP Block1 Handler
CVE-2026-58465 7.5 - High - July 02, 2026

Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion.

Allocation of Resources Without Limits or Throttling

In Eclipse Wakaama
CVE-2021-41040 7.5 - High - February 01, 2022

In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

Out-of-bounds Read

In Eclipse Wakaama (formerly liblwm2m) 1.0
CVE-2019-9004 - February 22, 2019

In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Eclipse Wakaama or by Eclipse? Click the Watch button to subscribe.

Eclipse
Vendor

subscribe