CVE-2026-33592: CWE-770 Allocation of resources without limits or throttling in open62541 project / o6 Automation GmbH open62541
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.
AI Analysis
Technical Summary
An unauthenticated remote attacker can exploit a resource exhaustion vulnerability in open62541's FindServers Discovery Service by sending an excessively large serverUris field in the FindServersRequest message. The server does not impose limits on the length or array size of this field and buffers incoming chunks in memory indefinitely until the SecureChannel times out. This leads to server memory exhaustion and potential denial of service. The vulnerability affects open62541 versions 1.4.0 through 1.4.16 and 1.5.0 through 1.5.4, as well as the master branch. The attack is pre-session and bypasses encryption, requiring no privileges or user interaction.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by exhausting server memory resources, potentially leading to server crashes or degraded performance. There is no impact on confidentiality or integrity as per the CVSS vector. The attack bypasses encryption and authentication mechanisms because it occurs before session establishment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, consider limiting exposure of the FindServers Discovery Service to untrusted networks or implementing network-level protections to detect and block abnormal large or incomplete requests targeting this service.
CVE-2026-33592: CWE-770 Allocation of resources without limits or throttling in open62541 project / o6 Automation GmbH open62541
Description
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/open62541/open62541Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An unauthenticated remote attacker can exploit a resource exhaustion vulnerability in open62541's FindServers Discovery Service by sending an excessively large serverUris field in the FindServersRequest message. The server does not impose limits on the length or array size of this field and buffers incoming chunks in memory indefinitely until the SecureChannel times out. This leads to server memory exhaustion and potential denial of service. The vulnerability affects open62541 versions 1.4.0 through 1.4.16 and 1.5.0 through 1.5.4, as well as the master branch. The attack is pre-session and bypasses encryption, requiring no privileges or user interaction.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by exhausting server memory resources, potentially leading to server crashes or degraded performance. There is no impact on confidentiality or integrity as per the CVSS vector. The attack bypasses encryption and authentication mechanisms because it occurs before session establishment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, consider limiting exposure of the FindServers Discovery Service to untrusted networks or implementing network-level protections to detect and block abnormal large or incomplete requests targeting this service.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ENISA
- Date Reserved
- 2026-03-23T12:53:47.475Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a46150227e9c79719683b17
Added to database: 07/02/2026, 07:36:34 UTC
Last enriched: 07/09/2026, 09:22:27 UTC
Last updated: 08/15/2026, 12:41:08 UTC
Views: 132
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.