CVE-2019-9004: Eclipse Wakaama
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.
Affected products
- Eclipse Wakaama: version 1.0 only
Published 2019-02-22. Last modified 2026-06-17.