id: PYSEC-2019-166 details: The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.g., the standard CoAP server, CoAP client, example collect CoAP server and client) when they receive crafted CoAP messages. affected: - package: name: coapthon3 ecosystem: PyPI purl: pkg:pypi/coapthon3 ranges: - type: ECOSYSTEM events: - introduced: '1.0' versions: - 1.0.1 - 1.0.2 references: - type: REPORT url: https://github.com/Tanganelli/CoAPthon3/issues/16 - type: ADVISORY url: https://github.com/advisories/GHSA-c6fm-rgw4-8q73 aliases: - CVE-2018-12679 - GHSA-c6fm-rgw4-8q73 modified: '2021-08-25T04:57:20.904496Z' published: '2019-04-02T19:29:00Z'