What is CVE-2026-67855?
CVE-2026-67855 is a heap use-after-free vulnerability in the open62541 library's GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service. If this functionality is active, a security patch should be applied or the configuration should be disabled.
Azərbaycanca: CVE-2026-67855, open62541 kitabxanasında GDS PushManagement sertifikat yeniləmə iş axınında aşkarlanan heap use-after-free zəifliyidir. Bu zəiflik UA_ENABLE_GDS_PUSHMANAGEMENT aktiv olduqda uzaqdan gələn hücumçuya denial of service yaratmağa imkan verir. Bu funksionallıq aktivdirsə, təhlükəsizlik yaması tətbiq edilməli və ya konfiqurasiya deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which specific functionality of open62541 is affected by CVE-2026-67855?
This vulnerability affects the GDS PushManagement certificate update workflow in the open62541 library. It can only be exploited when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.
What outcome can a remote attacker achieve by exploiting CVE-2026-67855?
A remote attacker can cause a denial of service by exploiting the CVE-2026-67855 heap use-after-free vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.