Denial of Service (DoS)
Description
FreeOPCUA library all versions vulnerable to DoS via memory exhaustion by sending multiple CloseSession requests with deleteSubscription=False.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FreeOPCUA library all versions vulnerable to DoS via memory exhaustion by sending multiple CloseSession requests with deleteSubscription=False.
Vulnerability
All versions of the freeopcua OPC UA library are vulnerable to a Denial of Service (DoS) attack via excessive memory consumption. The vulnerability occurs when an attacker sends multiple CloseSession requests with the deleteSubscription parameter set to False. This bypasses the intended memory consumption limitations, leading to unbounded memory allocation. [1][2]
Exploitation
An attacker with network access to a vulnerable freeopcua server can exploit this vulnerability by sending a series of crafted CloseSession requests. No authentication or special privileges are required. The attacker simply needs to send multiple requests with deleteSubscription=False, causing the server to allocate memory for each request without proper cleanup. [1]
Impact
Successful exploitation results in memory exhaustion on the server, leading to a Denial of Service (DoS). The server becomes unresponsive, disrupting legitimate OPC UA communications and potentially affecting industrial control systems relying on the library. [1]
Mitigation
As of the publication date, no fixed version of freeopcua is available. The vendor has been notified [2]. Administrators should consider implementing network-level restrictions, such as rate limiting or filtering of excessive CloseSession requests, and monitor memory usage on affected systems. If possible, switching to an alternative OPC UA library may be advisable. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- freeopcua/freeopcuadescription
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- github.com/FreeOpcUa/freeopcua/issues/391mitrex_refsource_MISC
- security.snyk.io/vuln/SNYK-UNMANAGED-FREEOPCUAFREEOPCUA-2988720mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.