logo

CVE-2026-54156: Unbounded Nonce Cache in node-opcua Causes DoS Vulnerability

ID: bc06d888-2e18-57ec-b50a-c033fa399002

STIX ID: report--bc06d888-2e18-57ec-b50a-c033fa399002

Feed Name: ThreatCluster

Threat Score
60/100

Date Published: 2026-08-22

Date Updated: 2026-08-23

...
...

A critical vulnerability (CVE-2026-54156) in node-opcua allows unauthenticated remote attackers to cause heap exhaustion and crash servers by exploiting an unbounded process-global nonce cache; affected versions are up to 2.165.0 and a fix is provided in 2.168.0 (CVSS 7.5).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.