Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11946

Опубликовано: 02 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.

A flaw was found in open62541. An unauthenticated remote attacker can exploit a vulnerability in the GetEndpoints Discovery Service by sending a malformed request with an excessively long, unvalidated endpointUrl field. This can lead to the server buffering large amounts of data indefinitely, causing server memory exhaustion and a Denial of Service (DoS) condition. This attack can occur before a secure session is established and bypasses encryption configurations.

Отчет

A flaw was found in open62541, an open-source OPC UA implementation. The GetEndpoints Discovery Service does not validate the length of the endpointUrl field in GetEndpointsRequest. An unauthenticated remote attacker can declare an arbitrarily large string (up to ~4 GB) delivered via intermediate chunks without sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out, causing memory exhaustion and denial of service. The attack is pre-session and bypasses all encryption configurations. Affected versions: 1.4.0 through 1.4.16, 1.5.0 through 1.5.4.

Меры по смягчению последствий

The issue has been fixed in v1.5.5.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2496476open62541: open62541: Denial of Service via unvalidated endpoint URL length

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.

CVSS3: 7.5
nvd
около 2 месяцев назад

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.

CVSS3: 7.5
debian
около 2 месяцев назад

An unauthenticated remote attacker can exhaust server memory via the G ...

CVSS3: 7.5
github
около 2 месяцев назад

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.

7.5 High

CVSS3