CVE-2026-67860
Received Received - Intake

Heap-based Buffer Overflow in open62541

Vulnerability report for CVE-2026-67860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: MITRE

Description

open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open62541 open62541 1.5.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap-based buffer overflow in open62541 version 1.5.5. It occurs in the default HistoryRead path when the default history database is used with the memory backend.

Impact Analysis

A heap-based buffer overflow can lead to crashes, data corruption, or arbitrary code execution. This may allow attackers to gain control over the affected system or disrupt its operations.

Compliance Impact

The provided CVE data does not specify how this vulnerability affects compliance with standards like GDPR or HIPAA. The vulnerability involves a heap-based buffer overflow in open62541, which could lead to denial of service or potential data corruption, but its direct impact on regulatory compliance is not described.

Mitigation Strategies

Upgrade open62541 to a version later than 1.5.5 to address the heap-based buffer overflow in the HistoryRead path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart