Executive brief
open62541 is an open-source OPC UA client and server library used in industrial automation and IoT systems. A malicious OPC UA server can crash open62541 client applications during the normal connection handshake by sending a specially crafted response, causing a denial of service. The vulnerability is triggered after a successful session activation when the client automatically reads the server's namespace array.
Technical details
The vulnerability is an out-of-bounds read in the responseReadNamespacesArray() function in src/client/ua_client_connect.c. When processing a Read response with resultsSize == 0 but with results encoded as an empty array (rather than NULL), the code decodes the array pointer as UA_EMPTY_ARRAY_SENTINEL (0x01). The vulnerable condition checks "if(!resp->results || !resp->results[0].value.data)" but because resp->results is non-NULL (0x01), the second operand dereferences resp->results[0] even though resultsSize is 0, causing an invalid memory read from the zero page. The attack requires network access to the OPC UA TCP port and occurs after completing the full connection handshake (HEL/ACK, OpenSecureChannel, FindServers, GetEndpoints, CreateSession, ActivateSession). The confirmed impact is deterministic client-side denial of service via process crash.
Affected products
- open62541 open62541 1.5.5
Timeline
- 2026-08-04: disclosed: Published on NVD
- other: Vulnerability identified in version 1.5.5; patch status unknown