CVE-2026-67863
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_loca
CVSS
7.5
High
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Aug 5, 2026 · Last modified: Aug 31, 2026 · CWE-416
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.
- github.comhttps://github.com/open62541/open62541/blob/v1.5.5/include/open62541/server.h
- github.comhttps://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_services_monitoreditem.c
- github.comhttps://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_subscription.c
- github.comhttps://github.com/open62541/open62541/issues/8131
- github.comhttps://github.com/open62541/open62541/issues/8131
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-918187.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.6hCVE-2026-918167.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.6hCVE-2026-918097.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.6hCVE-2026-918067.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.6hCVE-2026-918057.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.6hCVE-2026-917997.8 HIG8.4%
——3A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.6h