CVE-2026-67864
- EPSS 0.25%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 06.08.2026 15:17:24
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
CVE-2026-67863
- EPSS 0.41%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 07.08.2026 13:16:53
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem f...
CVE-2026-67869
- EPSS 0.47%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 06.08.2026 13:18:23
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
CVE-2026-67870
- EPSS 0.27%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 06.08.2026 22:18:23
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targ...
CVE-2026-67855
- EPSS 0.17%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 19:17:32
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
CVE-2026-67856
- EPSS 0.25%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 19:17:32
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests
CVE-2026-67857
- EPSS 0.35%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 15:17:06
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVE-2026-67858
- EPSS 0.49%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 15:17:06
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request...
CVE-2026-67861
- EPSS 0.42%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 16:17:00
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
CVE-2026-67859
- EPSS 0.47%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 16:17:00
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.