


Perceptive Security
SOC/SIEM Consultancy

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 23:03:20
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Network Infrastructure
A buffer overflow vulnerability has been identified in open62541 version 1.5.5, an open-source OPC UA (Open Platform Communications Unified Architecture) implementation. The vulnerability resides in the Discovery/LDS (Local Discovery Server) handling component. A remote attacker can exploit this flaw to cause a denial of service condition. The affected code paths include server_lds.c, ua_discovery_mdns.c, ua_services_discovery.c, and ua_util.c. The issue has been tracked and reported via GitHub issue #8095. Given that open62541 is widely used in industrial and IoT environments for OPC UA communications, this vulnerability poses a risk to critical infrastructure and industrial control systems. No patch version is referenced in the advisory at this time.
Technical details
Mitigation steps:
Affected products:
open62541 v1.5.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67859
https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c
https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c
https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c
https://github.com/open62541/open62541/blob/master/src/util/ua_util.c
https://github.com/open62541/open62541/issues/8095
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
