Hi, The fixed upstream maintenance release v1.4.18 is waiting to be released as a package update. The Salsa repository is ready: https://salsa.debian.org/jpfr/open62541
Thank you for verifying and pulling the trigger. Regards, Julius On Thu, 30 Jul 2026 at 07:17, Salvatore Bonaccorso <[email protected]> wrote: > Source: open62541 > Version: 1.4.11.1-1 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team < > [email protected]> > > Hi, > > The following vulnerability was published for open62541. > > CVE-2026-15690[0]: > | A vulnerability was identified in open62541 up to 1.5.5. Affected by > | this issue is the function responseReadNamespacesArray of the file > | src/client/ua_client_connect.c of the component Shared Client > | Library. Such manipulation of the argument Server_NamespaceArray > | leads to null pointer dereference. The attack can be executed > | remotely. The attack requires a high level of complexity. The > | exploitation is known to be difficult. The exploit is publicly > | available and might be used. The project closed the issue report, > | stating that this is not the official way to report a security > | vulnerability. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2026-15690 > https://www.cve.org/CVERecord?id=CVE-2026-15690 > [1] https://github.com/open62541/open62541/issues/8104 > > Please adjust the affected versions in the BTS as needed. > > Regards, > Salvatore >

