{"api_version":"1","generated_at":"2026-07-23T15:16:28+00:00","cve":"CVE-2026-33592","urls":{"html":"https://cve.report/CVE-2026-33592","api":"https://cve.report/api/cve/CVE-2026-33592.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-33592","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-33592"},"summary":{"title":"FindServers Memory Exhaustion in open62541","description":"An unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk. The\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.","state":"PUBLISHED","assigner":"ENISA","published_at":"2026-07-02 08:16:39","updated_at":"2026-07-02 17:39:07"},"problem_types":["CWE-770","CWE-789","CWE-770 CWE-770 Allocation of resources without limits or throttling","CWE-789 CWE-789 Memory allocation with excessive size value"],"metrics":[{"version":"3.1","source":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/open62541/open62541/pull/8142","name":"https://github.com/open62541/open62541/pull/8142","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/open62541/open62541","name":"https://github.com/open62541/open62541","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae","name":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae","refsource":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-33592","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33592","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected 1.4.0 1.4.16 semver","platforms":[]},{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected 1.5.0 1.5.4 semver","platforms":[]},{"source":"CNA","vendor":"open62541 project / o6 Automation GmbH","product":"open62541","version":"affected master custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lorenzo Cannella from Fondazione Ugo Bordoni (FUB)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"33592","cve":"CVE-2026-33592","epss":"0.003880000","percentile":"0.307790000","score_date":"2026-07-04","updated_at":"2026-07-05 00:02:26"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-33592","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-02T12:29:37.308768Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-02T12:30:18.800Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"open62541","vendor":"open62541 project / o6 Automation GmbH","versions":[{"lessThanOrEqual":"1.4.16","status":"affected","version":"1.4.0","versionType":"semver"},{"lessThanOrEqual":"1.5.4","status":"affected","version":"1.5.0","versionType":"semver"},{"status":"affected","version":"master","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Lorenzo Cannella from Fondazione Ugo Bordoni (FUB)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span>An unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk. The\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration. The&nbsp;</span>issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master."}],"value":"An unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk. The\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of resources without limits or throttling","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-789","description":"CWE-789 Memory allocation with excessive size value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-02T07:12:24.250Z","orgId":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","shortName":"ENISA"},"references":[{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142"},{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae"},{"tags":["product"],"url":"https://github.com/open62541/open62541"}],"source":{"advisory":"SA-2026-0002","discovery":"UNKNOWN"},"title":"FindServers Memory Exhaustion in open62541","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","assignerShortName":"ENISA","cveId":"CVE-2026-33592","datePublished":"2026-07-02T07:12:24.250Z","dateReserved":"2026-03-23T12:53:47.475Z","dateUpdated":"2026-07-02T12:30:18.800Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-02 08:16:39","lastModifiedDate":"2026-07-02 17:39:07","problem_types":["CWE-770","CWE-789","CWE-770 CWE-770 Allocation of resources without limits or throttling","CWE-789 CWE-789 Memory allocation with excessive size value"],"metrics":{"cvssMetricV31":[{"source":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-02T12:29:37.308768Z","id":"CVE-2026-33592","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"33592","Ordinal":"1","Title":"FindServers Memory Exhaustion in open62541","CVE":"CVE-2026-33592","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"33592","Ordinal":"1","NoteData":"An unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk. The\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.","Type":"Description","Title":"FindServers Memory Exhaustion in open62541"}]}}}