


Perceptive Security
SOC/SIEM Consultancy

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
Published:
4 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 01:03:20
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure, Network Infrastructure
CVE-2026-67857 affects open62541 version 1.5.5, an open-source OPC UA implementation widely used in industrial and IoT environments. The vulnerability is an out-of-bounds read located in the client-side function responseReadNamespacesArray() within src/client/ua_client_connect.c. This type of memory safety issue can potentially lead to information disclosure or application crashes when a malicious server sends a crafted response. The flaw is triggered during the client connection phase when namespace arrays are being read and processed. References include GitHub issues and source code links pointing to the exact affected files. The vulnerability has been assigned a high criticality level, suggesting significant risk to systems using this library version.
Technical details
Mitigation steps:
Affected products:
open62541 1.5.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67857
https://github.com/gff-cw/information/issues/9
https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c
https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c
https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c
https://github.com/open62541/open62541/issues/8104
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
