#1143975 open62541: CVE-2026-18784 CVE-2026-18785 CVE-2026-63035 CVE-2026-63362 CVE-2026-63559 CVE-2026-65423 CVE-2026-67855 CVE-2026-67856 CVE-2026-67857 CVE-2026-67858 CVE-2026-67859 CVE-2026-67860 CVE-2026-67861 CVE-2026-67862 CVE-2026-67863 CVE-2026-67864 CVE-2026-67869 CVE-2026-67870

Package:
src:open62541
Source:
src:open62541
Submitter:
Salvatore Bonaccorso
Date:
2026-08-09 07:01:02 UTC
Severity:
normal
Tags:
#1143975#5
Date:
2026-08-09 06:58:30 UTC
From:
To:
Hi,

The following vulnerabilities were published for open62541.

There were a lot of new issues which got CVEs, upstream issues were
closed with the note they were not reported according the the projects
SECURITY policy, can yo ucheck if those were still fixed?

CVE-2026-18784[0]:
| A vulnerability was found in o6 open62541 up to 1.5.5. This issue
| affects the function UA_Client_readNodeClassAttribute of the file
| src/client/ua_client_highlevel.c. Performing a manipulation results
| in heap-based buffer overflow. Attacking locally is a requirement.
| The exploit has been made public and could be used. The project
| closed the issue report, stating that this is not the official way
| to report a security vulnerability.


CVE-2026-18785[1]:
| A vulnerability was determined in o6 open62541
| ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function
| UA_Client_getRemoteDataTypes of the file
| examples/custom_datatype/client_types_custom.c. Executing a
| manipulation can lead to use after free. It is possible to launch
| the attack on the local host. The exploit has been publicly
| disclosed and may be utilized. The project closed the issue report,
| stating that this is not the official way to report a security
| vulnerability.


CVE-2026-63035[2]:
| A heap use-after-free vulnerability in the TransferSubscriptions
| service  in open62541 may allow an authenticated attacker to cause a
| denial of  service or potentially execute arbitrary code.


CVE-2026-63362[3]:
| An unsigned integer underflow in the PubSub signature verification
| path  in open62541 may allow a remote attacker to cause a denial of
| service  via a crafted UDP packet.


CVE-2026-63559[4]:
| An integer overflow in the UA_Variant arrayDimensions product
| computation in open62541 may allow a remote attacker to read  out-
| of-bounds heap memory, potentially disclosing sensitive information.


CVE-2026-65423[5]:
| An integer overflow in the UA_Variant arrayDimensions product
| computation in open62541 may allow a remote attacker to trigger an
| out-of-bounds write.


CVE-2026-67855[6]:
| open62541 contains a heap use-after-free in the GDS PushManagement
| certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is
| enabled. This allows a remote attacker to cause a denial of service.


CVE-2026-67856[7]:
| An issue in open62541 v.1.5.5 and before allows a remote attacker to
| cause a denial of service via crafted CreateSubscription,
| CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and
| DeleteSubscriptions requests


CVE-2026-67857[8]:
| open62541 1.5.5 contains an out-of-bounds read in the client-side
| function responseReadNamespacesArray() in
| src/client/ua_client_connect.c.


CVE-2026-67858[9]:
| Buffer Overflow vulnerability exists in open62541 1.5.5 when the
| Local Discovery Server (LDS) is built with multicast discovery
| enabled through the MDNSD backend. An unauthenticated remote
| attacker can send a RegisterServer or RegisterServer2 request
| containing many unique discoveryUrls. This allows remote attackers
| to cause a denial of service.


CVE-2026-67859[10]:
| Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote
| attacker to cause a denial of service via the Discovery/LDS
| handling.


CVE-2026-67860[11]:
| open62541 1.5.5 contains a heap-based buffer overflow in the default
| HistoryRead path when the default history database is used with the
| memory backend.


CVE-2026-67861[12]:
| An issue in open62541 v.1.5.5 and before allows a remote attacker to
| cause a denial of service via the UA_Client_getRemoteDataTypes
| component


CVE-2026-67862[13]:
| open62541 1.5.5 contains a buffer-overflow in the high-level
| attribute reading logic in src/client/ua_client_highlevel.c. This
| allows a remote attacker to cause a denial of service.


CVE-2026-67863[14]:
| In open62541 1.5.5, a server-side use-after-free exists in the local
| MonitoredItem callback path. The issue occurs when
| UA_Subscription_localPublish continues to use the current
| UA_Notification after a callback invokes
| UA_Server_deleteMonitoredItem for the current local MonitoredItem.
| This allows a remote attacker to cause a denial of service.


CVE-2026-67864[15]:
| An issue in open62541 v.1.5.5 and before allows a remote attacker to
| cause a denial of service via the NodeManagement type-instantiation
| logic component


CVE-2026-67869[16]:
| Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote
| attacker to cause a denial of service via the Service_Call validates
| input arguments against runtime-resolved InputArguments metadata


CVE-2026-67870[17]:
| In open62541 v1.5.5, the server-side AddReferences implementation
| contains an incomplete validation flaw for non-local ExpandedNodeId
| targets. A remote attacker can send a crafted AddReferencesRequest
| with an empty targetServerUri and a non-zero
| targetNodeId.serverIndex, causing the target node pointer to remain
| NULL while execution continues.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18784
https://www.cve.org/CVERecord?id=CVE-2026-18784
[1] https://security-tracker.debian.org/tracker/CVE-2026-18785
https://www.cve.org/CVERecord?id=CVE-2026-18785
[2] https://security-tracker.debian.org/tracker/CVE-2026-63035
https://www.cve.org/CVERecord?id=CVE-2026-63035
[3] https://security-tracker.debian.org/tracker/CVE-2026-63362
https://www.cve.org/CVERecord?id=CVE-2026-63362
[4] https://security-tracker.debian.org/tracker/CVE-2026-63559
https://www.cve.org/CVERecord?id=CVE-2026-63559
[5] https://security-tracker.debian.org/tracker/CVE-2026-65423
https://www.cve.org/CVERecord?id=CVE-2026-65423
[6] https://security-tracker.debian.org/tracker/CVE-2026-67855
https://www.cve.org/CVERecord?id=CVE-2026-67855
[7] https://security-tracker.debian.org/tracker/CVE-2026-67856
https://www.cve.org/CVERecord?id=CVE-2026-67856
[8] https://security-tracker.debian.org/tracker/CVE-2026-67857
https://www.cve.org/CVERecord?id=CVE-2026-67857
[9] https://security-tracker.debian.org/tracker/CVE-2026-67858
https://www.cve.org/CVERecord?id=CVE-2026-67858
[10] https://security-tracker.debian.org/tracker/CVE-2026-67859
https://www.cve.org/CVERecord?id=CVE-2026-67859
[11] https://security-tracker.debian.org/tracker/CVE-2026-67860
https://www.cve.org/CVERecord?id=CVE-2026-67860
[12] https://security-tracker.debian.org/tracker/CVE-2026-67861
https://www.cve.org/CVERecord?id=CVE-2026-67861
[13] https://security-tracker.debian.org/tracker/CVE-2026-67862
https://www.cve.org/CVERecord?id=CVE-2026-67862
[14] https://security-tracker.debian.org/tracker/CVE-2026-67863
https://www.cve.org/CVERecord?id=CVE-2026-67863
[15] https://security-tracker.debian.org/tracker/CVE-2026-67864
https://www.cve.org/CVERecord?id=CVE-2026-67864
[16] https://security-tracker.debian.org/tracker/CVE-2026-67869
https://www.cve.org/CVERecord?id=CVE-2026-67869
[17] https://security-tracker.debian.org/tracker/CVE-2026-67870
https://www.cve.org/CVERecord?id=CVE-2026-67870

Regards,
Salvatore