CVE-2026-63362 Details
Description
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.
A vulnerability exists in the PubSub signature verification process of o6 Automation's open62541 implementation. An unsigned integer underflow can occur when the length of a UDP packet is manipulated, potentially leading to a denial-of-service condition by causing the application to read unmapped memory.
o6 Automation has prepared mitigations and fixes for this vulnerability. Users are recommended to update to the latest version. The new version can be obtained by contacting o6 Automation or by downloading from their website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-191 | Integer Underflow (Wrap or Wraparound) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |