| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-65423 | 8.8 | high |
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.
|
| CVE-2026-63035 | 8.1 | high |
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
|
| CVE-2026-63559 | 7.5 | high |
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.
|
| CVE-2026-63362 | 5.9 | medium |
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.
|