PT-2026-93839 · Npm · Node-Opcua
CVE-2026-68904
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
node-opcua versions 2.0.0 through 2.169.0
Description
A combination of bugs in the client implementation leads to unlimited TCP socket accumulation in the FIN-WAIT-2 state during automatic reconnection, resulting in memory exhaustion and process crashes. This occurs when the
keepSessionAlive setting is enabled and the OPC UA server has a clock skew relative to the client, causing the server to return BadInvalidTimestamp responses.The issue involves two primary technical failures:
- The
ping server()function inClientSessionKeepAliveManagerincorrectly treats aBadInvalidTimestampServiceFault as a network outage, triggering a full transport-level reconnection on every keep-alive cycle. - The
on ACK response()function inClientTCP transportusessocket.end()instead ofsocket.destroy()after a failed HEL/ACK negotiation. This sends a TCP FIN but leaves the socket in the FIN-WAIT-2 state if the peer does not close the connection, leaking file descriptors and memory.
Recommendations
Update node-opcua to version 2.170.0.
As a temporary mitigation, disable the
keepSessionAlive setting to prevent the repeated reconnection cycle.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Opcua