CVE-2026-82623

Source
https://cve.org/CVERecord?id=CVE-2026-82623
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82623.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82623
Downstream
Published
2026-08-31T06:15:08.682Z
Modified
2026-09-01T03:46:34.398522882Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after free
Details

A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UADataValuebackendcopyRange of the file plugins/historydata/uahistorydatabackend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82623.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ]
}
References

Affected packages

Git / github.com/open62541/open62541

Affected ranges

Type
GIT
Repo
https://github.com/open62541/open62541
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "last_affected": "1.5.0"
        },
        {
            "introduced": "1.5.1"
        },
        {
            "last_affected": "1.5.1"
        },
        {
            "introduced": "1.5.2"
        },
        {
            "last_affected": "1.5.2"
        },
        {
            "introduced": "1.5.3"
        },
        {
            "last_affected": "1.5.3"
        },
        {
            "introduced": "1.5.4"
        },
        {
            "last_affected": "1.5.4"
        },
        {
            "introduced": "1.5.5"
        },
        {
            "last_affected": "1.5.5"
        }
    ]
}

Affected versions

1.*
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
v1.*
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82623.json"