{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anode-opcuanode-opcuanode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:node-opcua:node-opcua:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-68904"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["node-opcua (\u003e= 2.0.0, \u003c 2.170.0)","node-opcua-client (\u003e= 2.0.0, \u003c 2.170.0)","node-opcua-transport (\u003e= 2.0.0, \u003c 2.170.0)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","nodejs","opcua","resource-exhaustion"],"_cs_type":"advisory","_cs_vendors":["node-opcua"],"content_html":"\u003cp\u003eCVE-2026-68904 is a resource exhaustion vulnerability in the node-opcua library affecting versions prior to 2.170.0. The vulnerability arises from an improper reconnection logic when the client environment has a clock skew relative to the connected OPC UA server. When the server returns a BadInvalidTimestamp error due to timestamp validation failure, the node-opcua keepalive manager incorrectly interprets this as a fatal transport-level network outage. This triggers an immediate reconnection attempt every keepAliveInterval (default 3 seconds).\u003c/p\u003e\n\u003cp\u003eSimultaneously, the library's transport layer uses socket.end() rather than socket.destroy() during failed handshakes. This sends a TCP FIN but does not forcefully close the connection, resulting in orphaned sockets remaining in a FIN-WAIT-2 state indefinitely. The cumulative effect of rapid, repeated reconnections caused by the misidentified error, combined with the failure to properly clean up sockets, leads to file descriptor exhaustion and memory depletion, eventually resulting in an OOM-kill or process crash.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation (via natural clock drift or deliberate manipulation of the server timestamp) leads to a persistent denial-of-service condition for the node-opcua client process. Affected industrial automation systems relying on this library may experience total loss of connectivity to OPC UA servers, process interruptions, and unrecoverable service downtime. The bug has been confirmed in node-opcua versions 2.169.0 and below.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade node-opcua, node-opcua-client, and node-opcua-transport to version 2.170.0 or later to patch the connection handling logic.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, implement system-level monitoring for TCP socket counts on hosts running node-opcua services (e.g., ss -antp | grep FIN-WAIT-2).\u003c/li\u003e\n\u003cli\u003eSynchronize system clocks between OPC UA clients and servers using NTP or PTP to prevent the BadInvalidTimestamp error condition from triggering the flawed reconnection logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T19:07:28Z","date_published":"2026-09-16T19:07:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-node-opcua-socket-leak/","summary":"A vulnerability in node-opcua (CVE-2026-68904) causes TCP socket exhaustion and process crashes when clock skew triggers continuous reconnection cycles.","title":"Resource Exhaustion in node-opcua via TCP Socket Leak","url":"https://feed.craftedsignal.io/briefs/2026-09-node-opcua-socket-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:node-Opcua:node-Opcua:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}