


Perceptive Security
SOC/SIEM Consultancy

An unauthenticated remote attacker can exhaust
server memory via the FindServers Discovery Service in open62541. The
serverUris field of FindServersRequest is n…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 18:03:40
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure, Mobile & IoT
CVE-2026-33592 is a denial-of-service vulnerability in open62541, a popular open-source OPC-UA library used in industrial and IIoT environments. An unauthenticated remote attacker can exhaust server memory by abusing the FindServers Discovery Service. The serverUris field in FindServersRequest lacks validation for length or array size, allowing an attacker to declare arbitrarily large strings (~3.9 GB) sent across intermediate chunks without ever delivering the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out, leading to memory exhaustion. The attack requires no authentication, no active session, and bypasses all encryption configurations. Affected versions include open62541 1.4.0 through 1.4.16, 1.5.0 through 1.5.4, and the master branch. A fix is available via a pull request on the official GitHub repository.
Technical details
Mitigation steps:
Affected products:
open62541 1.4.0-1.4.16
open62541 1.5.0-1.5.4
open62541 master
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33592
https://github.com/open62541/open62541
https://github.com/open62541/open62541/pull/8142
https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
