CVE-2026-63035

Summary

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
o6 Automationopen625411.3.0 <= 1.3.17affected
o6 Automationopen625411.4.0 <= 1.4.16affected
o6 Automationopen625411.5.0 <= 1.5.4affected
o6 Automationopen62541masteraffected

Weaknesses

  • CWE-416: CWE-416 Use After Free

References