All 7 CVE vulnerabilities found in node-opcua, with AI-generated Chinese analysis, references, and POCs.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-68904 | node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion CWE-400 | 7.0 | High | 2026-09-16 |
| CVE-2026-69200 | node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation (Related to CVE-2024-57086) CWE-1321 | 3.7 | Low | 2026-09-16 |
| CVE-2026-54156 | node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS CWE-770 | 7.5 | High | 2026-09-14 |
| CVE-2026-54155 | node-opcua: Missing nonce verification in UserNameIdentityToken authentication CWE-347 | 7.7 | High | 2026-09-14 |
| CVE-2022-24375 | Denial of Service (DoS) | 7.5 | High | 2022-08-24 |
| CVE-2022-21208 | Denial of Service (DoS) | 7.5 | High | 2022-08-23 |
| CVE-2022-25231 | Denial of Service (DoS) | 7.5 | High | 2022-08-23 |
All 7 known CVE vulnerabilities affecting node-opcua with full Chinese analysis, references, and POCs where available.