CVE-2026-33592Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unauthenticated memory exhaustion in open62541 FindServers Discovery Service (CVE-2026-33592) open62541’s OPC UA FindServers Discovery Service mishandles FindServersRequest parsing, failing to validate the length and array size of the serverUris field. The root cause is improper input validation leading to unbounded buffering of attacker-controlled data across message chunks. An unauthenticated remote attacker can stream an arbitrarily large serverUris string in intermediate chunks and never send the final chunk, forcing the server to hold the partial payload in RAM until the SecureChannel times out, even before session establishment and regardless of encryption settings. Successful exploitation results in server memory exhaustion and denial of service, potentially taking down OPC UA endpoints and disrupting industrial communications. 👉 Affected: open62541 (versions not specified) | Upgrade to Vendor patch when available (No fix yet — treat as suspicious)

    Post summary

    CVE‑2026‑33592 denotes an unauthenticated memory‑exhaustion flaw in open62541’s OPC UA FindServers service; no patch yet but a vendor fix is expected.

    0001097
    232 followersView on X

Explore more