Denial of Service Vulnerability in Node-OPCUA by Node-OPCUA
CVE-2026-54156

7.5HIGH

Key Information:

Vendor

Node-opcua

Vendor
CVE Published:
14 September 2026

What is CVE-2026-54156?

Node-OPCUA, an OPC UA implementation for TypeScript and Node.js, has a vulnerability related to an unbounded cache of nonces that can lead to denial of service attacks. This issue arises from the g_alreadyUsedNonce cache, which records nonces without appropriate expiration or size limits, allowing unauthorized users to repeatedly create sessions. This can lead to excessive memory consumption and eventually crash the server process. The vulnerability has been addressed in version 2.166.0.

Affected Version(s)

node-opcua < 2.166.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.