Description
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from OpenSecureChannelRequest and CreateSession without expiration or a size limit. An unauthenticated remote attacker can repeatedly create sessions with unique nonces, causing entries to persist after session expiry and accumulate across connection cycles even when maxSessions=10 limits concurrent sessions. The resulting unbounded heap growth can exhaust the default Node.js heap and crash the node-opcua server process. This issue is fixed in version 2.166.0.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via heap exhaustion
Action: Patch
AI Analysis

Impact

The vulnerability in node‑opcua allows an unauthenticated remote attacker to continuously create sessions with unique nonces. Because the global nonce cache grows unboundedly without expiration or size limits, repeated session creation causes heap growth until the default Node.js heap is exhausted, leading to a server crash. This is a denial‑of‑service flaw stemming from uncontrolled memory usage (CWE‑770).

Affected Systems

Affected systems include the node‑opcua OPC UA implementation for TypeScript and Node.js provided by the node‑opcua project. All versions prior to 2.166.0 are impacted, as the g_alreadyUsedNonce cache in server_secure_channel_layer.ts did not enforce a maximum size or expiration policy. Users of any release lacking the 2.166.0 fix are vulnerable when they allow external session creation without rate limiting.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploit. Nonetheless, an attacker can execute the walk‑through described in the advisory by repeatedly creating sessions with unique nonces, causing the global nonce cache to grow unbounded, eventually exhausting the Node.js heap and crashing the node‑opcua server process.

Generated by OpenCVE AI on September 20, 2026 at 23:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade node‑opcua to version 2.166.0 or later to apply the fixed nonce cache size limit.
  • If upgrading immediately is not possible, limit session creation rate or enforce a per‑client nonce usage policy to reduce cache growth.
  • Increase the Node.js heap size with the `--max-old-space-size` flag and monitor memory usage to trigger restarts as a temporary safeguard.

Generated by OpenCVE AI on September 20, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6wvw-vrw4-363w node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Node-opcua Project
Node-opcua Project node-opcua
Vendors & Products Node-opcua Project
Node-opcua Project node-opcua

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from OpenSecureChannelRequest and CreateSession without expiration or a size limit. An unauthenticated remote attacker can repeatedly create sessions with unique nonces, causing entries to persist after session expiry and accumulate across connection cycles even when maxSessions=10 limits concurrent sessions. The resulting unbounded heap growth can exhaust the default Node.js heap and crash the node-opcua server process. This issue is fixed in version 2.166.0.
Title node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Node-opcua Project Node-opcua
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:35:48.958Z

Reserved: 2026-06-11T21:15:33.872Z

Link: CVE-2026-54156

cve-icon Vulnrichment

Updated: 2026-09-14T16:35:45.671Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:46.927

Modified: 2026-09-30T19:38:27.293

Link: CVE-2026-54156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling