Open62541
Products
1- 23 CVEs
Recent CVEs
23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67870 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing… | ||
| CVE-2026-65423 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write. | ||
| CVE-2026-63035 | Hig | 0.53 | 8.1 | 0.01 | Jul 30, 2026 | A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code. | ||
| CVE-2026-67869 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata | ||
| CVE-2026-67863 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local… | ||
| CVE-2026-67864 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component | ||
| CVE-2026-67862 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service. | ||
| CVE-2026-67861 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component | ||
| CVE-2026-67860 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. | ||
| CVE-2026-67859 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. | ||
| CVE-2026-67858 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique… | ||
| CVE-2026-67857 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. | ||
| CVE-2026-67856 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests | ||
| CVE-2026-67855 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service. | ||
| CVE-2026-63559 | Hig | 0.49 | 7.5 | 0.00 | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information. | ||
| CVE-2024-53429 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2024 | Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash. | ||
| CVE-2026-11946 | Hig | 0.42 | 7.5 | 0.00 | Jul 2, 2026 | An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length… | ||
| CVE-2026-33592 | Hig | 0.42 | 7.5 | 0.00 | Jul 2, 2026 | An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered… | ||
| CVE-2026-63362 | Med | 0.38 | 5.9 | 0.02 | Jul 30, 2026 | An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet. | ||
| CVE-2026-18785 | Med | 0.34 | 5.3 | 0.00 | Aug 4, 2026 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to… |
- risk 0.64cvss 9.8epss 0.01
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…
- risk 0.57cvss 8.8epss 0.01
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.
- risk 0.53cvss 8.1epss 0.01
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
- risk 0.49cvss 7.5epss 0.00
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
- risk 0.49cvss 7.5epss 0.00
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local…
- risk 0.49cvss 7.5epss 0.00
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
- risk 0.49cvss 7.5epss 0.00
open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.
- risk 0.49cvss 7.5epss 0.00
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
- risk 0.49cvss 7.5epss 0.00
open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
- risk 0.49cvss 7.5epss 0.00
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
- risk 0.49cvss 7.5epss 0.00
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique…
- risk 0.49cvss 7.5epss 0.00
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
- risk 0.49cvss 7.5epss 0.00
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests
- risk 0.49cvss 7.5epss 0.00
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
- risk 0.49cvss 7.5epss 0.00
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.
- risk 0.49cvss 7.5epss 0.01
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
- risk 0.42cvss 7.5epss 0.00
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length…
- risk 0.42cvss 7.5epss 0.00
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered…
- risk 0.38cvss 5.9epss 0.02
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.
- risk 0.34cvss 5.3epss 0.00
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to…