HIGH 7.7 GitHub
CVE-2026-54155
node-opcua missing nonce verification in UserNameIdentityToken authentication
**Summary**
A missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions.
**Affected versions:** <= 2.165.0
**Tested version:** 2.165.0
**CVSS Score:** 8.1 (High)
**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
**CWE:** CWE-347 Improper Verification of Cryptographic Signature
---
**Root Cause**
In
Affected Products
- npm/node-opcua <= 2.165.0
References
- https://github.com/advisories/GHSA-mq36-523m-x7vv
- https://github.com/node-opcua/node-opcua/security/advisories/GHSA-mq36-523m-x7vv
- https://github.com/advisories/GHSA-mq36-523m-x7vv
This high severity vulnerability with a CVSS score of 7.7 was published on 2026-08-20 via GitHub. Affected: npm/node-opcua <= 2.165.0.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.