CVE-2026-54156 | node-opcua up to 2.165.x Cache server_secure_channel_layer.ts nonceAlreadyBeenUsed denial of service
A vulnerability, which was classified as problematic, was found in node-opcua up to 2.165.x. The impacted element is the function nonceAlreadyBeenUsed of the file packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts of the component Cache. The manipulation results in denial of service.
This vulnerability was named CVE-2026-54156. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More