CVE-2026-11946
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations.
The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Vector CVSS N/A/L/N/N y acceso remoto sin autenticación ni privilegios → T1190. GetEndpoints permite exhaust de memoria sin sesión → T1499.004 (exhaustión de recursos).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-770, CWE-789
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-11946",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-11946",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-02T12:15:40.618622Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"affectedData": [
{
"vendor": "open62541 project / o6 Automation GmbH",
"product": "open62541",
"versions": [
{
"status": "affected",
"version": "1.4.0",
"versionType": "semver",
"lessThanOrEqual": "1.4.16"
},
{
"status": "affected",
"version": "1.5.0",
"versionType": "semver",
"lessThanOrEqual": "1.5.4"
},
{
"status": "affected",
"version": "master",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-02T12:16:54.740",
"references": [
{
"url": "https://github.com/open62541/open62541",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
},
{
"url": "https://github.com/open62541/open62541/pull/8142",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
},
{
"url": "https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"description": [
{
"lang": "en",
"value": "CWE-770"
},
{
"lang": "en",
"value": "CWE-789"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.\n\n\n\nThe issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master."
}
],
"lastModified": "2026-07-02T17:39:07.620",
"sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}