-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing resource limits in three key areas: 1) MessageChunk decoding lacked max_message_size checks (CWE-770), 2) TCP transport layer didn't properly enforce max_chunk_count per session (CWE-400), and 3) MessageWriter allowed unlimited chunk generation. The GitHub commit 6fb683c specifically adds these validations in these components, confirming they were previously missing. The functions directly handle message/chunk processing without the critical limits described in the CVE, making them root causes of the resource exhaustion vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| opcua | rust | < 0.11.0 | 0.11.0 |