CVE-2026-63559

Summary

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

Affected Software

VendorProductVersion RangeStatus
o6 Automationopen625411.3.0 <= 1.3.17affected
o6 Automationopen625411.4.0 <= 1.4.16affected
o6 Automationopen625411.5.0 <= 1.5.4affected
o6 Automationopen62541masteraffected

Weaknesses

  • CWE-190: CWE-190

References