{"id":"CVE-2026-18784","summary":"o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow","details":"A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.","modified":"2026-08-14T03:51:36.414287398Z","published":"2026-08-04T16:30:09.771Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18784.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18784.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18784"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-18784"},{"type":"ADVISORY","url":"https://vuldb.com/submit/857012"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/385786"},{"type":"REPORT","url":"https://github.com/gff-cw/information/issues/11"},{"type":"REPORT","url":"https://github.com/open62541/open62541/issues/8139"},{"type":"REPORT","url":"https://vuldb.com/vuln/385786/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open62541/open62541","events":[{"introduced":"b90fbfac5ef484089447bf5e3fe6ad7baaaebada"},{"last_affected":"3bdeed5dfe8309cecabf36e04afe956b7f72ebd8"}],"database_specific":{"extracted_events":[{"introduced":"1.5.0"},{"last_affected":"1.5.0"},{"introduced":"1.5.1"},{"last_affected":"1.5.1"},{"introduced":"1.5.2"},{"last_affected":"1.5.2"},{"introduced":"1.5.3"},{"last_affected":"1.5.3"},{"introduced":"1.5.4"},{"last_affected":"1.5.4"},{"introduced":"1.5.5"},{"last_affected":"1.5.5"}],"source":"AFFECTED_FIELD"}}],"versions":["1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18784.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}