FindServers Memory Exhaustion in open62541
Summary
| CVE | CVE-2026-33592 |
|---|---|
| State | PUBLISHED |
| Assigner | ENISA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-02 08:16:39 UTC |
| Updated | 2026-07-02 17:39:07 UTC |
| Description | An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.003880000 probability, percentile 0.307790000 (date 2026-07-04)
Problem Types: CWE-770 | CWE-789 | CWE-770 CWE-770 Allocation of resources without limits or throttling | CWE-789 CWE-789 Memory allocation with excessive size value
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Open62541 Project O6 Automation GmbH | Open62541 | affected 1.4.0 1.4.16 semver | Not specified |
| CNA | Open62541 Project O6 Automation GmbH | Open62541 | affected 1.5.0 1.5.4 semver | Not specified |
| CNA | Open62541 Project O6 Automation GmbH | Open62541 | affected master custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/open62541/open62541/pull/8142 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | github.com | |
| github.com/open62541/open62541 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | github.com | |
| github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e36... | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Lorenzo Cannella from Fondazione Ugo Bordoni (FUB) (en)
There are currently no legacy QID mappings associated with this CVE.