PT-2026-103082 · Apache · Apache Plc4X

·

CVE-2026-102509

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Apache PLC4X versions 0.10.0 through 0.13.1
Description Memory allocation with excessive size values, allocation of resources without limits, and uncontrolled recursion in the Java implementation of Apache PLC4X (PLC4J) can allow a malicious or impersonated device to exhaust the memory or stack of the client application, leading to a denial of service. In the OPC UA driver, these issues are reachable before authentication during the establishment of the secure channel and session. Technical details include:
  • Length-prefixed byte strings are allocated based on the size claimed on the wire before verifying the actual data received.
  • Generated protocol parsers pre-allocate lists based on element counts claimed on the wire, which can trigger multi-gigabyte allocations. This parser is used by all PLC4J drivers, with the OPC UA driver as a verified pre-authentication path.
  • The OPC UA driver fails to enforce negotiated maximum chunk counts and message sizes when accumulating message chunks.
  • The OPC UA driver pre-allocates collections using element counts received from the server.
  • Recursive protocol types are parsed without a nesting-depth limit.
Recommendations Upgrade to version 1.0.0.

Fix

Allocation of Resources Without Limits

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102509

Affected Products

Apache Plc4X