An unsigned integer underflow in the PubSub signature verification path
in open62541 may allow a remote attacker to cause a denial of service
via a crafted UDP packet.
o6 Automation has prepared mitigations and fixes to address these
issues and recommends that users update to the newest version. The new
version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact
or by downloading from the
following locations:
https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f
https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60
https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e
https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df
For more information, see open62541
Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or
contact o6 Automation: https://www.o6-automation.com/contact