High severity7.5NVD Advisory· Published Aug 24, 2022· Updated Jun 17, 2026
CVE-2022-24375
CVE-2022-24375
Description
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
node-opcuanpm | < 2.74.0 | 2.74.0 |
Affected products
3- cpe:2.3:a:node-opcua_project:node-opcua:*:*:*:*:*:node.js:*:*Range: <2.74.0
Patches
Vulnerability mechanics
References
6- github.com/node-opcua/node-opcua/commit/3fd46ec156e7718a506be41f3916310b6bdd0407nvdPatchThird Party AdvisoryVDB EntryWEB
- github.com/node-opcua/node-opcua/commit/7b5044b3f5866fbedc3efabd05e407352c07bd2fnvdPatchThird Party AdvisoryWEB
- github.com/node-opcua/node-opcua/pull/1182nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-NODEOPCUA-2988725nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vh4f-fgpp-x8x2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24375ghsaADVISORY
News mentions
0No linked articles in our index yet.