


Perceptive Security
SOC/SIEM Consultancy

An unauthenticated remote attacker can exhaust
server memory via the GetEndpoints Discovery Service in open62541. The
endpointUrl field of GetEndpointsRequest i…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 18:03:40
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure, Mobile & IoT
CVE-2026-11946 is a denial-of-service vulnerability in open62541, a popular open-source OPC UA library. An unauthenticated remote attacker can exhaust server memory by exploiting the GetEndpoints Discovery Service, where the endpointUrl field lacks length validation. The attacker declares an arbitrarily large string (up to ~4.09 GB) via the UInt32 length field, delivered in intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out, effectively causing memory exhaustion. The attack is pre-session, requires no authentication, and bypasses all encryption configurations. Affected versions include open62541 1.4.0 through 1.4.16, 1.5.0 through 1.5.4, and the master branch. A fix has been proposed via a pull request on the project's GitHub repository.
Technical details
Mitigation steps:
Affected products:
open62541 1.4.0-1.4.16
open62541 1.5.0-1.5.4
open62541 master
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-11946
https://github.com/open62541/open62541
https://github.com/open62541/open62541/pull/8142
https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
