CVE-2026-67855
Received Received - Intake

Heap Use-After-Free in open62541 GDS PushManagement

Vulnerability report for CVE-2026-67855, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: MITRE

Description

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open62541 open62541 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap use-after-free issue in the open62541 library. It occurs in the GDS PushManagement certificate update workflow when the UA_ENABLE_GDS_PUSHMANAGEMENT feature is enabled. A remote attacker can exploit this to cause a denial of service by freeing memory that is still in use.

Impact Analysis

The vulnerability allows a remote attacker to crash the affected system by triggering a denial of service. This could disrupt services relying on open62541, potentially leading to downtime or loss of functionality in applications using the library.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a denial-of-service issue in a specific library (open62541) rather than a data breach or privacy violation.

Mitigation Strategies

Disable UA_ENABLE_GDS_PUSHMANAGEMENT in the open62541 configuration to prevent the heap use-after-free vulnerability from being triggered.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67855. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart