What is CVE-2026-67858?
CVE-2026-67858 is a buffer overflow vulnerability in open62541 1.5.5 affecting the Local Discovery Server (LDS) when built with multicast discovery enabled via the MDNSD backend. An unauthenticated remote attacker can exploit this by sending a RegisterServer or RegisterServer2 request with numerous unique discoveryUrls. Users should update the open62541 library to the latest version and review MDNSD usage.
Azərbaycanca: CVE-2026-67858, open62541 1.5.5 versiyasında, MDNSD backend ilə multicast kəşfi aktiv olduqda Local Discovery Server (LDS)-də baş verən buffer overflow zəifliyidir. Doğrulanmamış uzaqdan hücumçu, çoxlu unikal discoveryUrls ehtiva edən RegisterServer/RegisterServer2 sorğusu göndərərək bu zəiflikdən istifadə edə bilər. İstifadəçilər open62541 kitabxanasını ən son versiyaya yeniləməli və MDNSD istifadəsini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
Which open62541 component is affected by CVE-2026-67858?
CVE-2026-67858 is a buffer overflow vulnerability affecting the Local Discovery Server (LDS) component in open62541 1.5.5 when built with multicast discovery enabled via the MDNSD backend.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.