{"api_version":"1","generated_at":"2026-07-23T15:30:44+00:00","cve":"CVE-2026-11946","urls":{"html":"https://cve.report/CVE-2026-11946","api":"https://cve.report/api/cve/CVE-2026-11946.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-11946","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-11946"},"summary":{"title":"GetEndpoints Memory Exhaustion in open62541","description":"An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.\n\n\n\nThe issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.","state":"PUBLISHED","assigner":"ENISA","published_at":"2026-07-02 12:16:54","updated_at":"2026-07-02 17:39:07"},"problem_types":["CWE-770","CWE-789","CWE-770 CWE-770 Allocation of resources without limits or throttling","CWE-789 CWE-789 Memory allocation with excessive size value"],"metrics":[{"version":"3.1","source":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/open62541/open62541/pull/8142","name":"https://github.com/open62541/open62541/pull/8142","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/open62541/open62541","name":"https://github.com/open62541/open62541","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae","name":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-11946","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11946","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected 1.4.0 1.4.16 semver","platforms":[]},{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected 1.5.0 1.5.4 semver","platforms":[]},{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected master custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lorenzo Cannella from Fondazione Ugo Bordoni (FUB)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"11946","cve":"CVE-2026-11946","epss":"0.003860000","percentile":"0.306110000","score_date":"2026-07-05","updated_at":"2026-07-06 00:01:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-11946","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-02T12:15:40.618622Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-02T12:15:49.245Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"open62541","vendor":"open62541 project / o6 Automation GmbH","versions":[{"lessThanOrEqual":"1.4.16","status":"affected","version":"1.4.0","versionType":"semver"},{"lessThanOrEqual":"1.5.4","status":"affected","version":"1.5.0","versionType":"semver"},{"status":"affected","version":"master","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Lorenzo Cannella from Fondazione Ugo Bordoni (FUB)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span>An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.</span>\n\n\n\n<span>The&nbsp;</span>issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master."}],"value":"An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.\n\n\n\nThe issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of resources without limits or throttling","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-789","description":"CWE-789 Memory allocation with excessive size value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-02T10:54:17.782Z","orgId":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","shortName":"ENISA"},"references":[{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142"},{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae"},{"tags":["product"],"url":"https://github.com/open62541/open62541"}],"source":{"advisory":"SA-2026-0002","discovery":"UNKNOWN"},"title":"GetEndpoints Memory Exhaustion in open62541","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","assignerShortName":"ENISA","cveId":"CVE-2026-11946","datePublished":"2026-07-02T10:54:17.782Z","dateReserved":"2026-06-10T21:38:14.592Z","dateUpdated":"2026-07-02T12:15:49.245Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-02 12:16:54","lastModifiedDate":"2026-07-02 17:39:07","problem_types":["CWE-770","CWE-789","CWE-770 CWE-770 Allocation of resources without limits or throttling","CWE-789 CWE-789 Memory allocation with excessive size value"],"metrics":{"cvssMetricV31":[{"source":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-02T12:15:40.618622Z","id":"CVE-2026-11946","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"11946","Ordinal":"1","Title":"GetEndpoints Memory Exhaustion in open62541","CVE":"CVE-2026-11946","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"11946","Ordinal":"1","NoteData":"An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.\n\n\n\nThe issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.","Type":"Description","Title":"GetEndpoints Memory Exhaustion in open62541"}]}}}