node-opcua
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting node-opcuapage 1 of 1
- CVE-2022-21208HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-23
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerab…
- CVE-2022-24375HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-24
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
- CVE-2022-25231HIGHCVSS 7.5EG 7.5✓ Fixed in 2.74.02022-08-23
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
Check whether node-opcua is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for node-opcua CVEs against the assets you own.
Start Free Scan →