GHSA-3jmw-8hr3-2j76CriticalCVSS 9.8

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete...

Published
August 6, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.

🔗 References (6)