Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.7) | 0.35% | — | Node-opcua-clientAI | 16/9/2026 | 24/9/2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitized field names and allows a __proto__.pollutedKey path to modify Object.prototype.… | |
| Pendiente de análisis | Alta (7) | 0.44% | — | Node-opcuaAI | 16/9/2026 | 30/9/2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes BadInvalidTimestamp responses. ClientSessionKeepAliveManager._ping_server treated… | |
| Pendiente de análisis | Alta (7.5) | 0.78% | — | Node-opcuaAI | 14/9/2026 | 30/9/2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from OpenSecureChannelRequest and CreateSession without… | |
| Pendiente de análisis | Alta (7.7) | 0.42% | — | Node-opcuaAI | 14/9/2026 | 30/9/2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNonce. An… | |
| Aplazada | Alta (7.5) | 0.44% | — | Node-opcua-alarm-conditionAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Modificada | Alta (7.5) | 1.2% | — | Freeopcua Opcua-asyncio | 3/10/2023 | 17/6/2026 | Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory. | |
| Modificada | Alta (7.5) | 0.52% | — | Freeopcua Opcua-asyncio | 3/10/2023 | 17/6/2026 | Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session. | |
| Modificada | Alta (7.5) | 1.4% | — | Opcua Project Opcua | 24/8/2022 | 17/6/2026 | The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed. | |
| Modificada | Alta (7.5) | 1.6% | — | Node-opcua Project Node-opcua | 24/8/2022 | 17/6/2026 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False. | |
| Modificada | Alta (7.5) | 1.3% | — | Opcua Project Opcua | 23/8/2022 | 17/6/2026 | The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the… | |
| Modificada | Alta (7.5) | 1.3% | — | Asyncua Project AsyncuaOpcua Project Opcua | 23/8/2022 | 17/6/2026 | All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks… | |
| Modificada | Alta (7.5) | 1.3% | — | Node-opcua Project Node-opcua | 23/8/2022 | 17/6/2026 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit. | |
| Analizada | Alta (7.5) | 0.92% | — | Freeopcua | 23/8/2022 | 17/6/2026 | All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False. | |
| Modificada | Alta (7.5) | 1.4% | — | Node-opcua Project Node-opcua | 23/8/2022 | 17/6/2026 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without… |