top of page
perceptive_background_267k.jpg

An unauthenticated remote attacker can exhaust
server memory via the GetEndpoints Discovery Service in open62541. The
endpointUrl field of GetEndpointsRequest i…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 18:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure, Mobile & IoT

CVE-2026-11946 is a denial-of-service vulnerability in open62541, a popular open-source OPC UA library. An unauthenticated remote attacker can exhaust server memory by exploiting the GetEndpoints Discovery Service, where the endpointUrl field lacks length validation. The attacker declares an arbitrarily large string (up to ~4.09 GB) via the UInt32 length field, delivered in intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out, effectively causing memory exhaustion. The attack is pre-session, requires no authentication, and bypasses all encryption configurations. Affected versions include open62541 1.4.0 through 1.4.16, 1.5.0 through 1.5.4, and the master branch. A fix has been proposed via a pull request on the project's GitHub repository.

Technical details

Mitigation steps:

Affected products:

open62541 1.4.0-1.4.16
open62541 1.5.0-1.5.4
open62541 master

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page