VulnSea

node-opcua vulnerabilities

CVEs whose affected-version data names the node-opcua package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-69200Low· 3.7PoC
6d ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitiz…

Twilightnode-opcua · node-opcuaEPSS 0.33%via NVD
CVE-2026-68904High· 7.0
6d ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes …

Twilightnode-opcua-transport · node-opcua-transportEPSS 0.42%via NVD
CVE-2026-54155High· 7.7
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

Twilightnode-opcua · node-opcuaEPSS 0.33%via NVD
CVE-2026-54156High· 7.5
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer…

Twilightnode-opcua · node-opcuaEPSS 0.55%via NVD
node-opcua vulnerabilities (CVEs) · VulnSea