These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-67870 record describes a critical vulnerability in open62541 v1.5.5. The server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues. O [truncated]
The CVE-2026-67869 vulnerability is a Buffer Overflow in open62541 v1.5.5, which allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected product deployments should be reviewed for exposure, and defensive actions should be take [truncated]
A server-side use-after-free vulnerability exists in open62541 1.5.5 within the local MonitoredItem callback path. This issue arises when UA_Subscription_localPublish continues to utilize the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. Consequently, a remote attacker could exploit this to cause a denial of service.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T22:17:07.680Z and has not been modified since then. CVE-2026-67864 is a denial of service vulnerability in open62541 v.1.5.5 and before via the NodeManagement type-instantiation logic component. This issue allows a remote attacker to cause a denial of service. Organizations using open62541 v.1.5. [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:16.597Z and has not been modified since then. The open62541 1.5.5 version contains a buffer-overflow vulnerability in the high-level attribute reading logic, allowing a remote attacker to cause a denial of service. This vulnerability affects organizations using open62541 1.5.5. Security tea [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:16.460Z and has not been modified since then. This CVE affects open62541 versions prior to 1.5.6. The vulnerability is related to the UA_Client_getRemoteDataTypes component, which could lead to a denial of service. Evidence is limited, and further verification is needed to determine the ful [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:16.357Z and has not been modified since then. The open62541 1.5.5 version contains a heap-based buffer overflow in the default HistoryRead path when using the default history database with the memory backend. This vulnerability can lead to potential crashes and data breaches. Users of open6 [truncated]
The CVE-2026-67859 record describes a Buffer Overflow vulnerability in open62541 v1.5.5, which allows a remote attacker to cause a denial of service via the Discovery/LDS handling. This issue has a CVSS score of 7.5 and is classified as HIGH. Organizations should review their deployments for potential exposure and prioritize patching to prevent potential denial of service attacks. The CVE record was publi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:16.087Z and has not been modified since then. CVE-2026-67858 is a buffer overflow vulnerability in open62541 1.5.5 with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique disco [truncated]
The open62541 version 1.5.5 contains an out-of-bounds read vulnerability in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. This vulnerability could potentially allow attackers to access sensitive information. The issue arises from improper handling of namespace arrays in the client-side implementation. Users of open62541 version 1.5.5 should verify their system c [truncated]
The CVE-2026-67856 vulnerability affects open62541 versions 1.5.5 and before, allowing remote attackers to cause a denial of service via crafted requests. Organizations should prioritize patching to prevent potential attacks. The vulnerability can be exploited through CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests. Evidence is limited t [truncated]
A vulnerability was identified in open62541 up to 1.5.5. The issue affects the function responseReadNamespacesArray in the file src/client/ua_client_connect.c of the Shared Client Library. This vulnerability leads to a null pointer dereference when manipulating the Server_NamespaceArray argument. The attack can be executed remotely but requires a high level of complexity. According to the project, the iss [truncated]