CVE-2026-54156: Unbounded Nonce Cache in node-opcua Causes DoS Vulnerability
ID: bc06d888-2e18-57ec-b50a-c033fa399002
STIX ID: report--bc06d888-2e18-57ec-b50a-c033fa399002
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-54156) in node-opcua allows unauthenticated remote attackers to cause heap exhaustion and crash servers by exploiting an unbounded process-global nonce cache; affected versions are up to 2.165.0 and a fix is provided in 2.168.0 (CVSS 7.5).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
