CVE-2026-67857
- EPSS 0.35%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVE-2026-67856
- EPSS 0.25%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests
CVE-2026-67855
- EPSS 0.17%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
CVE-2026-15690
- EPSS 0.27%
- Veröffentlicht 14.07.2026 12:16:55
- Zuletzt bearbeitet 14.07.2026 15:26:24
A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_Na...
CVE-2024-53429
- EPSS 0.71%
- Veröffentlicht 21.11.2024 15:15:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
CVE-2022-25761
- EPSS 1.38%
- Veröffentlicht 23.08.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:57
The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attack...
CVE-2020-36429
- EPSS 0.31%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:29
Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.