Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67863

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

A flaw was found in open62541. A server-side use-after-free vulnerability exists in the local MonitoredItem callback path. This occurs when the system attempts to use a notification object after it has been deallocated. A remote attacker can exploit this vulnerability to cause a denial of service (DoS), making the affected system unavailable.

Отчет

This Important flaw in open62541 allows a remote attacker to trigger a denial of service due to a use-after-free vulnerability in the server's MonitoredItem callback path. The issue arises from improper handling of notification objects after deallocation, leading to service unavailability. This is considered Important due to the potential for unauthenticated remote denial of service against affected open62541 server instances.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2511847open62541: open62541: Denial of Service via use-after-free vulnerability

EPSS

Процентиль: 34%
0.00405
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
27 дней назад

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

CVSS3: 7.5
nvd
27 дней назад

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

CVSS3: 7.5
debian
27 дней назад

In open62541 1.5.5, a server-side use-after-free exists in the local M ...

CVSS3: 7.5
github
27 дней назад

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

EPSS

Процентиль: 34%
0.00405
Низкий

7.5 High

CVSS3