CVE-2026-67857
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
Affected products
n/a · n/aReferences
https://github.com/gff-cw/information/issues/9https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.chttps://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.chttps://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.chttps://github.com/open62541/open62541/issues/8104