CVE-2022-25231: Allocation of Resources Without Limits or Throttling
(updated )
The package node-opcua before 2.74.0 is vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
References
Detect and mitigate CVE-2022-25231 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →