HIGH 7.5 GitHub

CVE-2026-54156

node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS

**Summary** A process-global nonce cache with no eviction policy allows an unauthenticated remote attacker to exhaust server heap memory by repeatedly opening sessions, causing the node-opcua server process to crash. **Affected versions:** <= 2.165.0 **Tested version:** 2.165.0 **CVSS Score:** 7.5 (High) **CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H **CWE:** CWE-770 Allocation of Resources Without Limits or Throttling --- **Root Cause** In `packages/node-opcua-secure-channel/

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-20 via GitHub. Affected: npm/node-opcua <= 2.165.0.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.