Junglewise Threat Intelligence

CVE-2026-67858: open62541 buffer overflow in Local Discovery Server multicast discovery

CVE-2026-67858 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Open62541.

Executive brief

open62541 is an open-source OPC UA (industrial automation) server library. When configured with multicast discovery enabled, an unauthenticated attacker on the network can crash the Local Discovery Server by sending malformed registration requests with many discovery URLs, causing a denial of service that interrupts industrial control and monitoring systems.

Technical details

A buffer overflow vulnerability exists in open62541 1.5.5's Local Discovery Server (LDS) when built with MDNSD multicast discovery enabled. The vulnerability is triggered when an unauthenticated remote attacker sends a RegisterServer or RegisterServer2 request containing many unique discoveryUrls, which overflow an internal buffer. The attack vector is network-accessible and requires no authentication or user interaction. Successful exploitation causes denial of service by crashing the LDS process. Patch availability for this CVE has not been confirmed from the provided information.

Affected products

  • open62541 open62541 1.5.5

Timeline

  • 2026-08-04: disclosed

References