Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6wvw-vrw4-363w | node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from OpenSecureChannelRequest and CreateSession without expiration or a size limit. An unauthenticated remote attacker can repeatedly create sessions with unique nonces, causing entries to persist after session expiry and accumulate across connection cycles even when maxSessions=10 limits concurrent sessions. The resulting unbounded heap growth can exhaust the default Node.js heap and crash the node-opcua server process. This issue is fixed in version 2.166.0. | |
| Title | node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T16:35:48.958Z
Reserved: 2026-06-11T21:15:33.872Z
Link: CVE-2026-54156
Updated: 2026-09-14T16:35:45.671Z
Status : Received
Published: 2026-09-14T17:17:46.927
Modified: 2026-09-14T17:17:46.927
Link: CVE-2026-54156
No data.
OpenCVE Enrichment
No data.
Github GHSA