PT-2026-93839 · Npm · Node-Opcua

CVE-2026-68904

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions node-opcua versions 2.0.0 through 2.169.0
Description A combination of bugs in the client implementation leads to unlimited TCP socket accumulation in the FIN-WAIT-2 state during automatic reconnection, resulting in memory exhaustion and process crashes. This occurs when the keepSessionAlive setting is enabled and the OPC UA server has a clock skew relative to the client, causing the server to return BadInvalidTimestamp responses.
The issue involves two primary technical failures:
  1. The ping server() function in ClientSessionKeepAliveManager incorrectly treats a BadInvalidTimestamp ServiceFault as a network outage, triggering a full transport-level reconnection on every keep-alive cycle.
  2. The on ACK response() function in ClientTCP transport uses socket.end() instead of socket.destroy() after a failed HEL/ACK negotiation. This sends a TCP FIN but leaves the socket in the FIN-WAIT-2 state if the peer does not close the connection, leaking file descriptors and memory.
Recommendations Update node-opcua to version 2.170.0. As a temporary mitigation, disable the keepSessionAlive setting to prevent the repeated reconnection cycle.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68904
GHSA-R2PF-9CW4-5J65

Affected Products

Node-Opcua