Impact
A defect in older node-opcua clients mishandles server scheduled keep‑alive failures caused by clock skew, causing the client to repeatedly reconnect. Each reconnection can leave sockets in a FIN‑WAIT‑2 state, draining file descriptors and memory until the process or container runs out of resources and must be terminated.
Affected Systems
vulnerable versions of node‑opcua range from 2.0.0 through 2.170.0. The issue was resolved in release 2.170.0. Users running these ranges should review their dependency versions.
Risk and Exploitability
With a CVSS score of 7 and an EPSS of less than 1%, the overall exploitation risk is moderate but the impact can be severe if an attacker can induce repeated keep‑alive retries. Based on the description, it is inferred that the vulnerability could be exploited from an external server that repeatedly returns BadInvalidTimestamp responses, forcing the client into the reconnection loop. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Github GHSA