Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qpgc-xh7j-52q8: node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limit

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.

ghsa
#vulnerability#dos#nodejs#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-25231

node-opcua DoS vulnerability via message with memory allocation that exceeds v8’s memory limit

High severity GitHub Reviewed Published Aug 24, 2022 • Updated Sep 1, 2022

Package

npm node-opcua (npm)

Affected versions

< 2.74.0

Description

Related news

CVE-2022-25231: Snyk Vulnerability Database | Snyk

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.