CVE-2026-67855: Use After Free
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UAENABLEGDSPUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable UA_ENABLE_GDS_PUSHMANAGEMENT in open62541 to avoid the heap use-after-free in the GDS PushManagement certificate update workflow.
open62541 UA_ENABLE_GDS_PUSHMANAGEMENT = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67855?
CVE-2026-67855 is classified with a risk score of 26, indicating significant severity due to its potential impact.
What type of vulnerability is CVE-2026-67855?
CVE-2026-67855 is a heap use-after-free vulnerability that can lead to a denial of service.
How does CVE-2026-67855 affect open62541?
CVE-2026-67855 affects open62541 when the GDS PushManagement feature is enabled, allowing remote attackers to exploit the vulnerability.
How do I fix CVE-2026-67855?
To mitigate CVE-2026-67855, disable the UA_ENABLE_GDS_PUSHMANAGEMENT feature or apply the relevant updates from the open62541 project.
When was CVE-2026-67855 published?
CVE-2026-67855 was published on August 4, 2026.