Node Opcua Project maintains a focused implementation of the OPC UA industrial-automation protocol for the Node.js runtime, serving as a connectivity layer for manufacturing systems and industrial IoT deployments. The vulnerability footprint centers on this single product line; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node Opcua Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24375HIGH The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requ | Aug 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-21208HIGH The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all | Aug 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25231HIGH The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested mem | Aug 23, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node Opcua Project.
Media articles that mention a CVE ID that affects a product developed by Node Opcua Project — matched by CVE ID, not by vendor name.