Cyber Resilience

CVE-2025-59391

Medium

Published: 08 December 2025

Published
08 December 2025
Modified
12 December 2025
KEV Added
Patch
CVSS Score v3.1 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score 0.0012 30.1th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-59391 is a medium-severity Out-of-bounds Read (CWE-125) vulnerability in Libcoap Libcoap. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 30.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This…

more

could potentially lead to information disclosure or denial of service.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

libcoap
libcoap
≤ 4.3.5a

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References