CVE-2025-65495: High severity OISM libcoap vulnerability
Published Nov 24, 2025
·Updated
Integer signedness error in tlsverifycallback() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2dX509() to return -1 and be misused as a malloc() size parameter.
Affected Software
2 affected components
OISM libcoap
libcoap libcoap=4.3.5
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65495?
CVE-2025-65495 is rated as a high severity vulnerability due to the potential for denial of service.
2
How do I fix CVE-2025-65495?
To fix CVE-2025-65495, update to the latest version of OISM libcoap where the vulnerability has been addressed.
3
What impact does CVE-2025-65495 have on OISM libcoap users?
CVE-2025-65495 allows remote attackers to cause a denial of service through a crafted TLS certificate.
4
Which versions of OISM libcoap are affected by CVE-2025-65495?
OISM libcoap version 4.3.5 is known to be vulnerable to CVE-2025-65495.
5
Can CVE-2025-65495 be exploited without authentication?
Yes, CVE-2025-65495 can be exploited by remote attackers without requiring authentication.