CVE-2023-26151: Freeopcua Opcua-Asyncio

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

Affected products

  • Freeopcua Opcua-Asyncio: before 0.9.96 (fixed in 0.9.96)

Published 2023-10-03. Last modified 2026-06-17.