CVE-2026-67855: Use After Free
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UAENABLEGDSPUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable UA_ENABLE_GDS_PUSHMANAGEMENT in open62541 to avoid the heap use-after-free in the GDS PushManagement certificate update workflow.
open62541 UA_ENABLE_GDS_PUSHMANAGEMENT = disabled