In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 00:16
Updated : 2026-08-31 19:33
NVD link : CVE-2026-67870
Mitre link : CVE-2026-67870
CVE.ORG link : CVE-2026-67870
JSON object : View
Products Affected
No product.
CWE
CWE-476
NULL Pointer Dereference
