PT-2026-68349 · Open62541 · Open62541
CVE-2026-67863
·
Published
2026-08-05
·
Updated
2026-08-07
CVSS v3.1
7.5
High
| Vector | AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
open62541 version 1.5.5
Description
A server-side use-after-free issue exists in the local MonitoredItem callback path. This occurs when the function
UA Subscription localPublish() continues to use the current UA Notification after a callback has invoked UA Server deleteMonitoredItem() for the current local MonitoredItem. A remote attacker can exploit this to cause a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open62541