CVE-2026-51535 Details
Description
In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.
A denial-of-service vulnerability has been identified in OpENer version 2.3.0 (commit 76b95cf). This issue arises in the TCP network handler, where the application processes all network traffic in a single-threaded event loop. The vulnerability can be exploited by an unauthenticated remote attacker who sends a specially crafted, incomplete Ethernet/IP packet header over an established TCP connection. This exploitation method, reminiscent of a Slowloris attack, causes the server to block indefinitely, disrupting normal communication and processing of legitimate requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/EIPStackGroup/OpENer/issues/562 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gist.github.com/MrAlaskan/bec306c51fec9f777b2599f5dea09dd1 | [email protected] | AdvisoryExploitTechnical Description |
| https://github.com/EIPStackGroup/OpENer/issues/562 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| EIPStackGroup OpENer | 2.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion