node-opcua
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting node-opcuapage 1 of 1
- CVE-2022-21208HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-23
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerab…
- CVE-2022-24375HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-24
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
- CVE-2022-25231HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-23
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
- CVE-2026-54155HIGHCVSS 7.7EG 7.72026-08-20
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not veri…
- CVE-2026-54156HIGHCVSS 7.5EG 7.5✓ Fixed in 2.166.02026-08-20
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.t…
Check whether node-opcua is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for node-opcua CVEs against the assets you own.
Start Free Scan →