High severity7.5NVD Advisory· Published Aug 4, 2026· Updated Aug 31, 2026
CVE-2026-67855
CVE-2026-67855
Description
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/open62541/open62541/blob/master/arch/posix/eventloop_posix.cnvd
- github.com/open62541/open62541/blob/master/examples/encryption/server_encryption.cnvd
- github.com/open62541/open62541/blob/master/src/server/ua_server_internal.hnvd
- github.com/open62541/open62541/blob/master/src/server/ua_server_ns0_gds.cnvd
- github.com/open62541/open62541/issues/8093nvd
News mentions
1- Open62541: 14 Critical and High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 6, 2026