{"id":"CVE-2026-67858","published":"2026-08-04T22:17:16.087","lastModified":"2026-08-05T15:17:06.617","description":"Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-120"],"vendors":[],"products":[],"references":[{"url":"https://github.com/open62541/open62541/blob/master/doc/building.rst","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8094","tags":[]},{"url":"https://github.com/open62541/open62541/tree/master/examples/discovery","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8094","tags":[]}],"exploitRefs":[{"url":"https://github.com/open62541/open62541/blob/master/doc/building.rst","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8094","tags":[]},{"url":"https://github.com/open62541/open62541/tree/master/examples/discovery","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8094","tags":[]}],"hasPoc":true,"ai":{"summary":"A buffer overflow vulnerability in open62541 1.5.5 allows unauthenticated remote attackers to cause a denial of service by sending malformed RegisterServer or RegisterServer2 requests.","exploitability":"Exploitation is relatively easy due to the lack of authentication and the specific nature of the request needed, requiring multicast discovery enabled through MDNSD backend.","blast_radius":"If exploited, it could lead to a denial of service for affected systems, impacting availability and potentially disrupting operations relying on open62541.","remediation":"Downgrade to a version prior to 1.5.5 or apply the available patch if one is released, disable multicast discovery in the Local Discovery Server configuration, or update to a newer version of open62541 that addresses this vulnerability.","tags":["dos","multicast","mdnsd","discovery","remote"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:55:31.853Z"}}