Junglewise Threat Intelligence

CVE-2026-67860: open62541 heap buffer overflow in HistoryRead continuation point handling

CVE-2026-67860 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Open62541.

Executive brief

open62541 is an open-source OPC UA server library used to expose industrial control systems and data historians over a network. A remote attacker can trigger a heap buffer overflow by sending a forged HistoryRead request with a malicious continuation point, causing the server to crash and become unavailable. The vulnerability requires the server to have historization enabled and use the default memory-backed history database.

Technical details

This is a heap-based buffer overflow in the default HistoryRead path (ua_history_database_default.c and ua_history_data_backend_memory.c). The vulnerability stems from a size_t underflow when an attacker-controlled skip value in a HistoryRead continuation point exceeds the internal result size. The outer layer allocates a small buffer based on the clamped result size, but then passes a very large (wrapped) valueSize to the backend copy function, which writes far more entries than the allocated buffer can hold. The attack is remotely reachable via the normal TCP HistoryRead service without authentication. Confirmed impact is remote denial of service (server crash); code execution has not been demonstrated.

Affected products

  • open62541 open62541 1.5.5 and master branch (commit 10022ffbcc92d823be4c51dd96cfd350f8e351e7)

Timeline

  • 2026-08-04: disclosed: Published on NVD

References