CVE-2026-67855
Published: Tue, 04 Aug 2026 22:17
Summary
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
Are YOU affected by CVE-2026-67855?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-67855 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://github.com/open62541/open62541
- https://github.com/open62541/open62541/blob/master/arch/posix/eventloop_posix.c
- https://github.com/open62541/open62541/blob/master/examples/encryption/server_encryption.c
- https://github.com/open62541/open62541/blob/master/src/server/ua_server_internal.h
- https://github.com/open62541/open62541/blob/master/src/server/ua_server_ns0_gds.c
- https://github.com/open62541/open62541/issues/8093
- https://github.com/open62541/open62541/issues/8093
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.