In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-63252 is a denial-of-service vulnerability affecting Eclipse Milo, an OPC UA implementation library used in industrial control systems and IoT applications. The flaw exists in UASC (OPC UA Secure Channel) server transport handlers that fail to properly release memory allocated for partial message chunks when client connections terminate unexpectedly. An unauthenticated remote attacker can exploit this by repeatedly sending incomplete message fragments and disconnecting, causing retained memory chunks to accumulate in the server's direct memory pool. Because this memory is pooled and finite, the server can be starved of available resources, leading to service degradation or complete termination. Organizations running Milo-based OPC UA servers in manufacturing, energy, or infrastructure environments face operational risk, as attackers require no authentication and can launch attacks from any network position.
While MITRE ATT&CK technique mappings are not yet assigned to this CVE, the attack pattern aligns with Resource Exhaustion tactics (T1499 and related denial-of-service vectors). Casky's AI-driven analysis, powered by Claude's extended reasoning capabilities, would correlate suspicious indicators across your security telemetry: repeated rapid connections from unauthenticated sources, incomplete protocol handshakes followed by abrupt disconnects, steady degradation of server memory availability, and error logs showing channel closure without proper cleanup. A practitioner using Casky would see findings highlighting the sequence of incomplete UASC chunks, the absence of connection cleanup events, and memory pressure correlations—enabling them to distinguish this targeted memory attack from legitimate network failures and apply targeted mitigation such as connection rate limiting, memory pool monitoring, and immediate patching.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-63252. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation