Advisory Information
- Repository Advisory URL: GHSA-r2pf-9cw4-5j65
- Advisory ID: GHSA-r2pf-9cw4-5j65
- CVE ID: CVE-2026-68904
- Ecosystem: npm
- Affected Packages:
node-opcua
node-opcua-client
node-opcua-transport
- Affected Versions:
>= 2.0.0, < 2.170.0
- Patched Versions:
2.170.0
- CWE: CWE-400 (Uncontrolled Resource Consumption)
- CVSS v3.1:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Credits
- Reporter / Finder: @Velluso (Credit has already been formally accepted on the repository advisory)
- Remediation Developer: @erossignon
Details
The repository advisory has been published by the maintainer (@erossignon) and patched since version 2.170.0, with the CVE ID (CVE-2026-68904) already assigned on the repository draft. However, it has not yet been ingested into the Global Advisory Database (GitHub-Reviewed).
Could you please review and promote this advisory to the Global Database so that:
- It receives GitHub-Reviewed status.
- The CVE metadata is synced properly.
- The reporter credit (@Velluso) is preserved and mapped to the user profile?
Thank you!
Advisory Information
node-opcuanode-opcua-clientnode-opcua-transport>= 2.0.0, < 2.170.02.170.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HCredits
Details
The repository advisory has been published by the maintainer (@erossignon) and patched since version
2.170.0, with the CVE ID (CVE-2026-68904) already assigned on the repository draft. However, it has not yet been ingested into the Global Advisory Database (GitHub-Reviewed).Could you please review and promote this advisory to the Global Database so that:
Thank you!