Open62541 is an open-source implementation of the OPC UA industrial-automation protocol, widely embedded in manufacturing, energy, and critical-infrastructure applications where it facilitates real-time machine communication and control. Its vulnerability footprint concentrates on the protocol parser and resource-management layers, with observed weakness classes including unthrottled resource allocation and out-of-bounds writes that reflect the parsing and memory-safety demands of a binary protocol handler. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open62541 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25761HIGH The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - | Aug 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-36429MEDIUM Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth. | Jul 20, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open62541.
Media articles that mention a CVE ID that affects a product developed by Open62541 — matched by CVE ID, not by vendor name.