---
id: CVE-2026-107838
title: >-
  RIOT is an open-source microcontroller operating system designed for Internet
  of Things devices and other embedded systems
summary: >-
  RIOT is an open-source microcontroller operating system designed for Internet
  of Things devices and other embedded systems. From version 2023.07 through
  version 2026.07, nanocoap_fileserver callers in
  sys/net/application_layer/nanocoap/f…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-252
  - CWE-617
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T18:17:05.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107838'
references:
  - url: >-
      https://github.com/RIOT-OS/RIOT/commit/d3a47289c58d108575a19e623e4d3f647659e743
    label: security-advisories@github.com
  - url: 'https://github.com/RIOT-OS/RIOT/pull/22745'
    label: security-advisories@github.com
  - url: 'https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-39j3-3v73-5mj2'
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T19:09:33.756Z'
---

## Overview

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
