Medium · 4.7 Node.js & npm GHSA-r2pf-9cw4-5j65 CVE-2026-68904
node-opcua: Resource Exhaustion Vulnerability via Keepalive Reconnection Cycle (CVE-2026-68904)
A flaw in node-opcua's session keepalive handling can trigger an endless reconnection loop when a server's clock skew causes timestamp errors, leading to file descriptor and memory exhaustion. Fixed in version 2.170.0.
AI summary
A vulnerability has been identified in node-opcua, an OPC UA implementation for TypeScript and Node.js, affecting the core package as well as its node-opcua-transport and node-opcua-client components. The issue, tracked as CVE-2026-68904 (GHSA-r2pf-9cw4-5j65), can cause affected clients to exhaust system resources under specific server conditions. A fix is available in version 2.170.0.
What happened
node-opcua clients that use the default keepSessionAlive setting can enter a repeated reconnection cycle when connected to an OPC UA server experiencing clock skew. The clock skew causes the server to return BadInvalidTimestamp responses, which the client's keepalive logic misinterprets as a network outage rather than a server-originated fault.
Technical cause
The root cause lies in two components working together. ClientSessionKeepAliveManager._ping_server treats a server-originated ServiceFault (caused by the BadInvalidTimestamp condition) as if it were a network outage, triggering a forced transport reconnect. Separately, ClientTCP_transport._on_ACK_response calls socket.end() after a failed HEL/ACK negotiation, which can leave the TCP connection in a FIN-WAIT-2 state if the remote peer does not close its side. Because this sequence repeats at the configured keepAliveInterval, file descriptors and memory accumulate over time.
Why it matters
The classification is Uncontrolled Resource Consumption (CWE-400). As sockets accumulate in FIN-WAIT-2 and are not released, the client process or its containing environment can eventually be terminated due to resource exhaustion. This can result in a denial of service for applications relying on node-opcua for OPC UA connectivity, with impact described in the CVSS vector as low confidentiality impact, low integrity impact, and high availability impact.
Who is affected
Any application using the node-opcua, node-opcua-transport, or node-opcua-client npm packages with the default keepSessionAlive setting, connecting to an OPC UA server that can exhibit clock skew sufficient to trigger BadInvalidTimestamp responses, is potentially affected.
Affected versions
Versions from 2.0.0 up to (but not including) 2.170.0 of node-opcua, node-opcua-transport, and node-opcua-client are affected.
Fixes and mitigation
The issue is fixed in version 2.170.0 of node-opcua, node-opcua-transport, and node-opcua-client. No alternative mitigation is described in the available facts beyond upgrading.
Recommended action
Update node-opcua and related packages (node-opcua-transport, node-opcua-client) to version 2.170.0 or later. Organizations unable to update immediately should monitor client processes for unusual growth in open file descriptors or sockets stuck in FIN-WAIT-2 as an indicator of this condition.
PatchBriefing score
4.7 / 10 · Medium
Official CVSS: 7.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Why this score
This issue carries a CVSS base score of 7.0 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H), reflecting network exploitability without authentication or user interaction, though with high attack complexity, and primarily high impact on availability. The computed PatchBriefing score of 4.7 reflects that there is no known exploitation in the wild, no public exploit, and no EPSS data available, while still accounting for the unauthenticated, no-interaction-required nature of the trigger condition and the fact that a fix is already available.
Affected versions
- node-opcua >= 2.0.0, < 2.170.0
- vulnerable
- ≥ 2.170.0
- patched
- node-opcua-transport >= 2.0.0, < 2.170.0
- vulnerable
- ≥ 2.170.0
- patched
- node-opcua-client >= 2.0.0, < 2.170.0
- vulnerable
- ≥ 2.170.0
- patched
Reported fixes
The issue is fixed in version 2.170.0 of node-opcua, node-opcua-transport, and node-opcua-client. No alternative mitigation is described in the available facts beyond upgrading.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email