Impact
The vulnerability in node‑opcua allows an unauthenticated remote attacker to continuously create sessions with unique nonces. Because the global nonce cache grows unboundedly without expiration or size limits, repeated session creation causes heap growth until the default Node.js heap is exhausted, leading to a server crash. This is a denial‑of‑service flaw stemming from uncontrolled memory usage (CWE‑770).
Affected Systems
Affected systems include the node‑opcua OPC UA implementation for TypeScript and Node.js provided by the node‑opcua project. All versions prior to 2.166.0 are impacted, as the g_alreadyUsedNonce cache in server_secure_channel_layer.ts did not enforce a maximum size or expiration policy. Users of any release lacking the 2.166.0 fix are vulnerable when they allow external session creation without rate limiting.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploit. Nonetheless, an attacker can execute the walk‑through described in the advisory by repeatedly creating sessions with unique nonces, causing the global nonce cache to grow unbounded, eventually exhausting the Node.js heap and crashing the node‑opcua server process.
OpenCVE Enrichment
Github GHSA