← Back

CVE-2022-25761

nvd nist
Published: Aug 23, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

Affected (6)

1 product
Open62541
1 product
Fedora
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Open62541
Before 1.2.5
Version 1.3 rc1
Version 1.3 rc2-ef2
Version 1.3 rc2-ef
Version 1.3 rc2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 37

References (12)

Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
Release NotesThird Party Advisory
Source: report@snyk.io
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.