node-opcua 是面向 TypeScript 和 Node.js 的 OPC UA 实现。在 2.166.0 版本之前, 中由 使用的进程级全局 缓存,会记录来自 和 的非重复值(nonce),但这些记录既没有过期机制,也没有大小限制。未经身份验证的远程攻击者可以通过反复创建带有唯一 nonce 的会话,导致这些条目在会话过期后仍然保留,并随着连接周期的循环不断累积,即使 限制了并发会话数量。由此产生的无界堆内存增长可能导致默认的 Node.js 堆内存耗尽,从而使 node-opcua 服务器进程崩溃。该问
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| node-opcua | node-opcua | < 2.166.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| node-opcua | node-opcua | < 2.166.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet