VYPR

npm package

node-opcua

pkg:npm/node-opcua

Vulnerabilities (4)

  • CVE-2026-68904HigSep 16, 2026
    affected >= 2.0.0, < 2.170.0fixed 2.170.0

    node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes BadInvalidTimestamp responses. ClientSessio

  • CVE-2022-24375HigAug 24, 2022
    affected < 2.74.0fixed 2.74.0

    The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

  • CVE-2022-25231HigAug 23, 2022
    affected < 2.74.0fixed 2.74.0

    The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.

  • CVE-2022-21208HigAug 23, 2022
    affected < 2.74.0fixed 2.74.0

    The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of h