
🚨 HIGH - Unauthenticated memory exhaustion in open62541 FindServers Discovery Service (CVE-2026-33592) open62541’s OPC UA FindServers Discovery Service mishandles FindServersRequest parsing, failing to validate the length and array size of the serverUris field. The root cause is improper input validation leading to unbounded buffering of attacker-controlled data across message chunks. An unauthenticated remote attacker can stream an arbitrarily large serverUris string in intermediate chunks and never send the final chunk, forcing the server to hold the partial payload in RAM until the SecureChannel times out, even before session establishment and regardless of encryption settings. Successful exploitation results in server memory exhaustion and denial of service, potentially taking down OPC UA endpoints and disrupting industrial communications. 👉 Affected: open62541 (versions not specified) | Upgrade to Vendor patch when available (No fix yet — treat as suspicious)
Post summary
CVE‑2026‑33592 denotes an unauthenticated memory‑exhaustion flaw in open62541’s OPC UA FindServers service; no patch yet but a vendor fix is expected.
