HIGH 7.7 GitHub

CVE-2026-54155

node-opcua missing nonce verification in UserNameIdentityToken authentication

**Summary** A missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions. **Affected versions:** <= 2.165.0 **Tested version:** 2.165.0 **CVSS Score:** 8.1 (High) **CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L **CWE:** CWE-347 Improper Verification of Cryptographic Signature --- **Root Cause** In

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This high severity vulnerability with a CVSS score of 7.7 was published on 2026-08-20 via GitHub. Affected: npm/node-opcua <= 2.165.0.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.