Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate. | |
| Title | S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items() | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T12:22:01.806Z
Reserved: 2026-09-13T12:01:31.544Z
Link: CVE-2026-90782
No data.
Status : Received
Published: 2026-09-13T13:16:29.410
Modified: 2026-09-13T13:16:29.410
Link: CVE-2026-90782
No data.
OpenCVE Enrichment
No data.