CVE-2026-63035

Summary

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
o6 Automationopen625411.3.0 <= 1.3.17affected
o6 Automationopen625411.4.0 <= 1.4.16affected
o6 Automationopen625411.5.0 <= 1.5.4affected
o6 Automationopen62541masteraffected

Weaknesses

  • CWE-416: CWE-416 Use After Free

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References