


Perceptive Security
SOC/SIEM Consultancy

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backen…
Published:
4 August 2026 at 00:00:00
Alert date:
5 August 2026 at 01:03:20
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure
A buffer overflow vulnerability exists in open62541 version 1.5.5 affecting the Local Discovery Server (LDS) when built with multicast discovery enabled via the MDNSD backend. An unauthenticated remote attacker can exploit this by sending a RegisterServer or RegisterServer2 request containing a large number of unique discoveryUrls. The vulnerability results in a denial of service condition. No authentication is required to trigger the vulnerability, making it accessible to any remote attacker. The affected component is the OPC UA server library's discovery and multicast DNS subsystem. Relevant source files include ua_discovery_mdns.c and ua_services_discovery.c. The issue is tracked on GitHub under issue #8094.
Technical details
Mitigation steps:
Affected products:
open62541 1.5.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67858
https://github.com/open62541/open62541/blob/master/doc/building.rst
https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c
https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c
https://github.com/open62541/open62541/issues/8094
https://github.com/open62541/open62541/tree/master/examples/discovery
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
