CVE Explorer
CVE-2026-11946
An unauthenticated remote attacker can exhaust
server memory via the GetEndpoints Discovery Service in open62541. The
endpointUrl field of GetEndpointsRequest is not validated for length. An
attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32
length field) delivered across intermediate chunks without ever sending the
final chunk. The server buffers all chunks in RAM indefinitely until the
SecureChannel times out. The attack is
pre-session and bypasses all encryption c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-770","description":"CWE-770 Allocation of resources without limits or throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-789","description":"CWE-789 Memory allocation with excessive size value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"open62541","vendor":"open62541 project / o6 Automation GmbH","versions":[{"lessThanOrEqual":"1.4.16","status":"affected","version":"1.4.0","versionType":"semver"},{"lessThanOrEqual":"1.5.4","status":"affected","version":"1.5.0","versionType":"semver"},{"status":"affected","version":"master","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-770","description":"CWE-770 Allocation of resources without limits or throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-789","description":"CWE-789 Memory allocation with excessive size value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"tags":["product"],"url":"https://github.com/open62541/open62541"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/references/2
{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/references/0
{"tags":["patch"],"url":"https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a266b26a009d4204915dc876bf5c16b07fa9d4841c6a67604ad9487d3ee39475 · sha256:495c2ab763f085da… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.