A vulnerability, which was classified as critical, was found in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function
UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-18785. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The project closed the issue report, stating that this is not the official way to report a security vulnerability.