HIGH
CVE-2026-67858
CVSS
7.5
Description
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.
Weakness (CWE)
CWE-120
Classic Buffer Overflow
EPSS Score
0.48%
Probability of exploitation in next 30 days
40.6th percentile
References
https://github.com/open62541/open62541/blob/master/doc/building.rst
https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c
https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c
https://github.com/open62541/open62541/issues/8094
https://github.com/open62541/open62541/tree/master/examples/discovery
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.