top of page
perceptive_background_267k.jpg

An unauthenticated remote attacker can exhaust
server memory via the FindServers Discovery Service in open62541. The
serverUris field of FindServersRequest is n…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 18:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Network Infrastructure, Mobile & IoT

CVE-2026-33592 is a denial-of-service vulnerability in open62541, a popular open-source OPC-UA library used in industrial and IIoT environments. An unauthenticated remote attacker can exhaust server memory by abusing the FindServers Discovery Service. The serverUris field in FindServersRequest lacks validation for length or array size, allowing an attacker to declare arbitrarily large strings (~3.9 GB) sent across intermediate chunks without ever delivering the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out, leading to memory exhaustion. The attack requires no authentication, no active session, and bypasses all encryption configurations. Affected versions include open62541 1.4.0 through 1.4.16, 1.5.0 through 1.5.4, and the master branch. A fix is available via a pull request on the official GitHub repository.

Technical details

Mitigation steps:

Affected products:

open62541 1.4.0-1.4.16
open62541 1.5.0-1.5.4
open62541 master

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page