HIGH 7.0 GitHub
CVE-2026-68904
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
SUMMARY
-------
A combination of bugs in node-opcua causes unlimited TCP socket accumulation (FIN-WAIT-2 state) during automatic reconnection, leading to memory exhaustion and eventual container/process crash (OOM kill). The issue is triggered by the default configuration (keepSessionAlive: true) when the OPC UA server has clock skew relative to the client.
Affected version: Tested on 2.169.0 (latest as of April 2026).
ENVIRONMENT
-----------
- Node.js: v24.11.0
- node-opcua: 2.169.0
- OS: Lin
Affected Products
- npm/node-opcua-transport >= 2.0.0, < 2.170.0
- npm/node-opcua-client >= 2.0.0, < 2.170.0
- npm/node-opcua >= 2.0.0, < 2.170.0
References
- https://github.com/advisories/GHSA-r2pf-9cw4-5j65
- https://github.com/node-opcua/node-opcua/security/advisories/GHSA-r2pf-9cw4-5j65
- https://github.com/node-opcua/node-opcua/pull/1497
- https://github.com/node-opcua/node-opcua/commit/1959cbb8946b386d2e24a1cce05b7148099d36e7
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-09-16 via GitHub. Affected: npm/node-opcua-transport >= 2.0.0, < 2.170.0, npm/node-opcua-client >= 2.0.0, < 2.170.0, npm/node-opcua >= 2.0.0, < 2.170.0.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.