What is CVE-2026-61387?
In Eclipse Milo OPC UA server library, monitored-item quota accounting is not exception-safe: if item creation fails, the server-global reservation is not restored. This can lead to a `StackOverflow` error when processing `CreateMonitoredItems` requests with deeply nested PubSub ExtensionObjects. Updating affected systems is recommended.
Azərbaycanca: Eclipse Milo OPC UA server kitabxanasında monitorinq elementi kvotasının idarə edilməsi istisna təhlükəsiz deyil: uğursuz element yaradılması zamanı server səviyyəli rezervasiya bərpa olunmur. Bu, xüsusilə dərin iç-içə PubSub ExtensionObjects ilə işlənən `CreateMonitoredItems` sorğularında `StackOverflow` xətasına səbəb ola bilər. Təsirə məruz qalan versiyaları istifadə edən sistemlərdə serveri yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Eclipse Milo
FAQ1
Under what condition can the CVE-2026-61387 vulnerability in the Eclipse Milo OPC UA server library lead to a StackOverflow error?
When processing `CreateMonitoredItems` requests with deeply nested PubSub ExtensionObjects, if item creation fails, the server-global monitored-item quota reservation is not restored, which can lead to a `StackOverflow` error.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.