{"id":"CVE-2026-26456","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-26456","summary":"A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition…","details":"A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization.","published":"2026-08-27T17:17:48.147","modified":"2026-08-27T17:17:48.147","cvss":null,"epss":{"score":0.00172,"percentile":0.06783,"asOf":"2026-08-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ipflavors/ccoap"},{"type":"WEB","url":"https://github.com/songxpu/bug_report/blob/master/CoAP/ccoap/VULNERABILITY_REPORT5.md"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T17:17:48.147"}}