HIGH 7.5 GitHub
CVE-2026-54156
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
**Summary**
A process-global nonce cache with no eviction policy allows an unauthenticated remote attacker to exhaust server heap memory by repeatedly opening sessions, causing the node-opcua server process to crash.
**Affected versions:** <= 2.165.0
**Tested version:** 2.165.0
**CVSS Score:** 7.5 (High)
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**CWE:** CWE-770 Allocation of Resources Without Limits or Throttling
---
**Root Cause**
In `packages/node-opcua-secure-channel/
Affected Products
- npm/node-opcua <= 2.165.0
References
- https://github.com/advisories/GHSA-6wvw-vrw4-363w
- https://github.com/node-opcua/node-opcua/security/advisories/GHSA-6wvw-vrw4-363w
- https://github.com/node-opcua/node-opcua/releases/tag/v2.168.0
- https://github.com/advisories/GHSA-6wvw-vrw4-363w
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-20 via GitHub. Affected: npm/node-opcua <= 2.165.0.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.